CVE-2018-3665
published 2018-06-21CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data…
PriorityP424medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.61%
45.3th percentile
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
Affected
503 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra_10.13.6_security_update_2018-004_sierra_security_update_2018-0 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.6.1-1 (bookworm) | linux 4.6.1-1 (bookworm) |
| debian | xen | < linux 4.6.1-1 (bookworm) | linux 4.6.1-1 (bookworm) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
Information Disclosure in WildFire Appliance (WF-500)
vendor_paloalto·2019-07-08·CVSS 5.6
CVE-2018-3665 [MEDIUM] CWE-200 Information Disclosure in WildFire Appliance (WF-500)
Information Disclosure in WildFire Appliance (WF-500)
Palo Alto Networks has determined that the WildFire Appliance (WF-500) is affected by the vulnerability disclosure known as LazyFP and has completed an update to address these issues. The WildFire Appliance (WF-500) software update is now available to customers that use the WildFire Appliance (WF-500) for on-premise sandboxing. Please note that customers using the WildFire cloud service are NOT impacted by this advisory. (PAN-99016/CVE-2018-3665)
Successful exploitation of this issue may allow reads from a compromised sandbox VM (guest OS) to retrieve data from other VMs (another guest OS) or the PAN-OS operating system (host OS) as a result of breaching the separation between kernel and user address space. The analysis method utilize
Apple
CVE-2018-3665: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
vendor_apple·2018-07-09·CVSS 5.6
CVE-2018-3665 [MEDIUM] CVE-2018-3665: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
Product: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
CVE: CVE-2018-3665
Component: Kernel
Impact: Systems using Intel® Core-based microprocessors may potentially allow a local process to infer data utilizing Lazy FP state restore from another process through a speculative execution side channel
Description: Lazy FP state restore instead of eager save and restore of the state upon a context switch. Lazy restored states are potentially vulnerable to exploits where one process may infer register values of other processes through a speculative execution side channel that infers their value.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 7.8
CVE-2017-13695 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an integer overflow existed in the perf subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (system crash). (CVE-2017-18255)
Wei Fang discovered an integer overflow in the F2FS filesystem
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service. (CVE-2017-18257)
It was discovered that an information leak existed in the generic SCSI
driver in the Linux kernel. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2018-1000204)
It was discovered that the wait4() system call in the Linux kernel did not
properly validate its arguments in some situations. A
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 7.8
CVE-2017-13695 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3696-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that an integer overflow existed in the perf subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (system crash). (CVE-2017-18255)
Wei Fang discovered an integer overflow in the F2FS filesystem
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service. (CVE-2017-18257)
It was discovered that an information leak existed in the generic SCSI
driver in the Linux kernel. A l
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 7.1
CVE-2017-12154 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)
It was discovered that a race condition existed in the ALSA subsystem of
the Linux kernel when creating and deleting a port via ioctl(). A loc
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 7.1
CVE-2017-12154 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3698-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local at
BSD
FreeBSD-SA-18:07.lazyfpu: Lazy FPU State Restore Information Disclosure
bsd_advisories·2018-06-21·CVSS 5.6
CVE-2018-3665 [MEDIUM] FreeBSD-SA-18:07.lazyfpu: Lazy FPU State Restore Information Disclosure
FreeBSD-SA-18:07.lazyfpu Security Advisory
The FreeBSD Project
Topic: Lazy FPU State Restore Information Disclosure
Category: core
Module: kernel
Announced: 2018-06-21
Credits: Julian Stecklina from Amazon Germany
Thomas Prescher from Cyberus Technology GmbH
Zdenek Sojka from SYSGO AG
Colin Percival
Affects: All supported version of FreeBSD.
Corrected: 2018-06-14 18:50:49 UTC (stable/11, 11.2-PRERELEASE)
2018-06-15 13:21:37 UTC (releng/11.2, 11.2-RC3)
2018-06-21 05:17:13 UTC (releng/11.1, 11.1-RELEASE-p11)
CVE Name: CVE-2018-3665
Special Note: This advisory only addresses this issue for FreeBSD 11.x on
i386 and amd64. We expect to update this advisory to include
10.x in the near future.
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields
Red Hat
Kernel: FPU state information leakage via lazy FPU restore
vendor_redhat·2018-06-13·CVSS 5.6
CVE-2018-3665 [MEDIUM] CWE-200 Kernel: FPU state information leakage via lazy FPU restore
Kernel: FPU state information leakage via lazy FPU restore
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
A Floating Point Unit (FPU) state information leakage flaw was found in the way the Linux kernel saved and restored the FPU state during task switch. Linux kernels that follow the "Lazy FPU Restore" scheme are vulnerable to the FPU state information leakage issue. An unprivileged local attacker could use this flaw to read FPU state bits by conducting targeted cache side-channel attacks, similar to the Meltdown vulnerability disclosed earlier this year.
Statement: This issue affects the versions of the Linu
Debian
CVE-2018-3665: linux - System software utilizing Lazy FP state restore technique on systems using Intel...
vendor_debian·2018·CVSS 5.6
CVE-2018-3665 [MEDIUM] CVE-2018-3665: linux - System software utilizing Lazy FP state restore technique on systems using Intel...
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
Scope: local
bookworm: resolved (fixed in 4.6.1-1)
bullseye: resolved (fixed in 4.6.1-1)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.6.1-1)
Citrix
Citrix Security Bulletin CTX235745
vendor_citrix·CVSS 5.6
CVE-2018-3665 [MEDIUM] Citrix Security Bulletin CTX235745
Citrix Security Bulletin CTX235745
CVE References: CVE-2018-3665, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-723g-x9c7-6562: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to i
ghsa_unreviewed·2022-05-13
CVE-2018-3665 [MEDIUM] CWE-200 GHSA-723g-x9c7-6562: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to i
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-07-02·CVSS 7.8
CVE-2017-18255 [HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3696-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that an integer overflow existed in the perf subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (system crash). (CVE-2017-18255)
Wei Fang discovered an integer overflow in the F2FS filesystem
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service. (CVE-2017-18257)
It was discovered that an information leak existed in the generic SCSI
driver in the Linux kernel. A local attacker could use this to expose
sensitive information (kernel me
OSV
linux vulnerabilities
osv·2018-07-02·CVSS 7.1
CVE-2017-12154 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)
It was discovered that a race condition existed in the ALSA subsystem of
the Linux kernel when creating and deleting a port via ioctl(). A local
attacker could use this to cause a denial of service (system crash) or
possib
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-07-02·CVSS 7.8
CVE-2017-18255 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that an integer overflow existed in the perf subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (system crash). (CVE-2017-18255)
Wei Fang discovered an integer overflow in the F2FS filesystem
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service. (CVE-2017-18257)
It was discovered that an information leak existed in the generic SCSI
driver in the Linux kernel. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2018-1000204)
It was discovered that the wait4() system call in the Linux kernel did not
properly validate its arguments in some situations. A local attacker could
possi
OSV
CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to i
osv·2018-06-21·CVSS 5.6
CVE-2018-3665 [MEDIUM] CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to i
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
No detection rules found.
No public exploits indexed.
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15·CVSS 5.6
[MEDIUM] 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Blog / Research
Subscribe
# 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Pablo Ramos
November 15, 2018
5 Min Read
The classes of vulnerabilities that brought us Meltdown and Spectre are not going away anytime soon. Here’s what you need to know about Speculative Execution vulnerabilities, with our guidance on steps you can take to reduce your risk.
Spectre and Meltdown generated a lot of confusion and discussion in the security world when they first hit the news. Understanding the risks associated with speculative execution vulnerabilities will help organizations prioritize and communicate effectively about their exposure. In this post, we present what it is known, how it affects companies and ways to stay ahead in the game.
## Start from the beginning…
Speculative Ex
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15
5W1H: Speculative Side Channel Vulnerabilities De-mystified
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2018-3665 Kernel: FPU state information leakage via lazy FPU restore
bugzilla·2018-06-01·CVSS 5.6
CVE-2018-3665 [MEDIUM] CVE-2018-3665 Kernel: FPU state information leakage via lazy FPU restore
CVE-2018-3665 Kernel: FPU state information leakage via lazy FPU restore
An information leakage flaw is found in the way Linux kernel saves and restores Floating Point Unit(FPU) state during task switch. There are two ways, one is to save & restore FPU state during task context switch. And second is to defer FPU state save & restore until an FP instruction is invoked by the current task. First is called as "Eager FPU Restore" and second is known as "Lazy FPU Restore" scheme.
Linux kernel which follows the "Lazy FPU Restore" scheme is vulnerable to the FPU state information leakage issue. An unprivileged local attacker could use this flaw to read FPU state bits by conducting targeted cache side-channel attacks, similar to Meltdown attack disclosed earlier this year.
Upstream fix:
-> http
arXiv
LazyFP: Leaking FPU Register State using Microarchitectural Side-Channels
arxiv_fulltext·2018-06-19
LazyFP: Leaking FPU Register State using Microarchitectural Side-Channels
## Abstract
Modern processors utilize an increasingly large register set to
facilitate efficient floating point and SIMD computation. This large
register set is a burden for operating systems, as its content needs to
be saved and restored when the operating system context switches between
tasks. As an optimization, the operating system can defer the context
switch of the FPU and SIMD register set until the first instruction is
executed that needs access to these registers. Meanwhile, the old
content is left in place with the hope that the current task might not
use these registers at all. This optimization is commonly called lazy
FPU context switching. To make it possible, a processor offers the
ability to toggle the availability of instructions utilizing floating
point and SIMD registers
http://www.securityfocus.com/bid/104460http://www.securitytracker.com/id/1041124http://www.securitytracker.com/id/1041125https://access.redhat.com/errata/RHSA-2018:1852https://access.redhat.com/errata/RHSA-2018:1944https://access.redhat.com/errata/RHSA-2018:2164https://access.redhat.com/errata/RHSA-2018:2165https://access.redhat.com/errata/RHSA-2019:1170https://access.redhat.com/errata/RHSA-2019:1190https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/4787https://security.FreeBSD.org/advisories/FreeBSD-SA-18:07.lazyfpu.aschttps://security.netapp.com/advisory/ntap-20181016-0001/https://security.paloaltonetworks.com/CVE-2018-3665https://support.citrix.com/article/CTX235745https://usn.ubuntu.com/3696-1/https://usn.ubuntu.com/3696-2/https://usn.ubuntu.com/3698-1/https://usn.ubuntu.com/3698-2/https://www.debian.org/security/2018/dsa-4232https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.synology.com/support/security/Synology_SA_18_31http://www.securityfocus.com/bid/104460http://www.securitytracker.com/id/1041124http://www.securitytracker.com/id/1041125https://access.redhat.com/errata/RHSA-2018:1852https://access.redhat.com/errata/RHSA-2018:1944https://access.redhat.com/errata/RHSA-2018:2164https://access.redhat.com/errata/RHSA-2018:2165https://access.redhat.com/errata/RHSA-2019:1170https://access.redhat.com/errata/RHSA-2019:1190https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://nvidia.custhelp.com/app/answers/detail/a_id/4787https://security.FreeBSD.org/advisories/FreeBSD-SA-18:07.lazyfpu.aschttps://security.netapp.com/advisory/ntap-20181016-0001/https://security.paloaltonetworks.com/CVE-2018-3665https://support.citrix.com/article/CTX235745https://usn.ubuntu.com/3696-1/https://usn.ubuntu.com/3696-2/https://usn.ubuntu.com/3698-1/https://usn.ubuntu.com/3698-2/https://www.debian.org/security/2018/dsa-4232https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.synology.com/support/security/Synology_SA_18_31
2018-06-21
Published