CVE-2018-3646

Severity
5.6MEDIUM
EPSS
3.9%
top 11.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 13

Description

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 1.1 | Impact: 4.0

Affected Packages20 packages

Debianxen< 4.11.1~pre.20180911.5acdd26fdc+dfsg-2+3
Debianlinux< 4.17.15-1+3
Ubuntulinux< 3.13.0-155.205+3
Ubuntulinux-aws< 4.4.0-1065.75+1
Ubuntulinux-kvm< 4.4.0-1031.37+1

🔴Vulnerability Details

11
GHSA
GHSA-qj7r-58vw-6www: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the2022-05-13
OSV
intel-microcode vulnerabilities2018-08-27
OSV
linux regressions2018-08-17
OSV
linux vulnerabilities2018-08-14
CVEList
CVE-2018-3646: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the2018-08-14

📋Vendor Advisories

17
VMware
VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabiliti2019-05-14
Ubuntu
Linux kernel vulnerabilities2018-11-15
Apple
CVE-2018-3646: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra2018-10-30
Apple
CVE-2018-3646: macOS Mojave 10.142018-09-24
Ubuntu
Intel Microcode vulnerabilities2018-08-27

🕵️Threat Intelligence

1
Huntress
CVE-2018-3646 Vulnerability: Analysis, Impact, Mitigation | Huntress

💬Community

2
Bugzilla
CVE-2018-3620 CVE-2018-3646 kernel: hw: cpu: L1 terminal fault (L1TF) [fedora-all]2018-08-14
Bugzilla
CVE-2018-3620 CVE-2018-3646 Kernel: hw: cpu: L1 terminal fault (L1TF)2018-06-01