CVE-2018-3693
published 2018-07-10CVE-2018-3693: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local…
PriorityP336medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
8.42%
94.4th percentile
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
Affected
912 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-a | — | — |
| arm | cortex-r | — | — |
| arm | cortex-r | — | — |
| debian | linux | < linux 4.15.11-1 (bookworm) | linux 4.15.11-1 (bookworm) |
| fujitsu | m12-1_firmware | < xcp3090 | xcp3090 |
| fujitsu | m12-2_firmware | < xcp3090 | xcp3090 |
| fujitsu | m12-2s_firmware | < xcp3090 | xcp3090 |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_oracle5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5hg-j44c-8mvh: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit
ghsa_unreviewed·2022-05-13
CVE-2018-3693 [MEDIUM] GHSA-v5hg-j44c-8mvh: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
OSV
CVE-2018-3693: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit
osv·2018-07-10·CVSS 5.6
CVE-2018-3693 [MEDIUM] CVE-2018-3693: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (Kernel) — CVE-2018-3693
vendor_oracle·2020-10-15·CVSS 5.6
CVE-2018-3693 [MEDIUM] Oracle Oracle Systems Risk Matrix: XCP Firmware (Kernel) — CVE-2018-3693
Oracle Oracle Systems Risk Matrix: XCP Firmware (Kernel) vulnerability
CVE: CVE-2018-3693
CVSS: 5.6
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2020 (OCT 2020)
Red Hat
Kernel: speculative bounds check bypass store
vendor_redhat·2018-07-10·CVSS 5.6
CVE-2018-3693 [MEDIUM] CWE-200 Kernel: speculative bounds check bypass store
Kernel: speculative bounds check bypass store
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions past bounds check. The flaw relies on the presence of a precisely-defined instruction sequence in the privileged code and the fact that memory writes occur to an address which depends on the untrusted value. Such writes cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged att
Debian
CVE-2018-3693: linux - Systems with microprocessors utilizing speculative execution and branch predicti...
vendor_debian·2018·CVSS 5.6
CVE-2018-3693 [MEDIUM] CVE-2018-3693: linux - Systems with microprocessors utilizing speculative execution and branch predicti...
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
Scope: local
bookworm: resolved (fixed in 4.15.11-1)
bullseye: resolved (fixed in 4.15.11-1)
forky: resolved (fixed in 4.15.11-1)
sid: resolved (fixed in 4.15.11-1)
trixie: resolved (fixed in 4.15.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3693 kernel: speculative bounds check bypass store [fedora-all]
bugzilla·2018-07-10·CVSS 5.6
CVE-2018-3693 [MEDIUM] CVE-2018-3693 kernel: speculative bounds check bypass store [fedora-all]
CVE-2018-3693 kernel: speculative bounds check bypass store [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2018-3693 Kernel: speculative bounds check bypass store
bugzilla·2018-05-23·CVSS 5.6
CVE-2018-3693 [MEDIUM] CVE-2018-3693 Kernel: speculative bounds check bypass store
CVE-2018-3693 Kernel: speculative bounds check bypass store
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions past bounds check.
It relies on the presence of a precisely-defined instruction sequence in the privileged code and the fact that memory writes occur to an address which depends on the untrusted value. Such writes cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire).
As a result, an unprivileged attacker could use this flaw to influence speculative execution and/or read privileged memory by conducting targeted cache side-channel attacks.
Discussion:
Statement:
This issue affects the versions of the Linux kernel as
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
- Introduction
- Targeted attack campaigns
- Mobile APT campaigns
- Exploits
- Browser extensions – extending the reach of cybercriminals
- The World Cup of fraud
- Financial fraud on an industrial scale
- Ransomware – still a threat
- Asacub and banking Trojans
- Smart doesn’t mean secure
- Our data in their hands
Authors
- David Emm
- Victor Chebyshev
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Story of the year: miners
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses a
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
Introduction
Targeted attack campaigns
Mobile APT campaigns
Exploits
Browser extensions – extending the reach of cybercriminals
The World Cup of fraud
Financial fraud on an industrial scale
Ransomware – still a threat
Asacub and banking Trojans
Smart doesn’t mean secure
Our data in their hands
Authors
David Emm
Victor Chebyshev
Kaspersky Security Bulletin 2018. Statistics
Kaspersky Security Bulletin 2018. Story of the year: miners
Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses and consumers provide
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15·CVSS 5.6
[MEDIUM] 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Blog / Research
Subscribe
# 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Pablo Ramos
November 15, 2018
5 Min Read
The classes of vulnerabilities that brought us Meltdown and Spectre are not going away anytime soon. Here’s what you need to know about Speculative Execution vulnerabilities, with our guidance on steps you can take to reduce your risk.
Spectre and Meltdown generated a lot of confusion and discussion in the security world when they first hit the news. Understanding the risks associated with speculative execution vulnerabilities will help organizations prioritize and communicate effectively about their exposure. In this post, we present what it is known, how it affects companies and ways to stay ahead in the game.
## Start from the beginning…
Speculative Ex
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15
5W1H: Speculative Side Channel Vulnerabilities De-mystified
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
Speculative Buffer Overflows: Attacks and Defenses
arxiv_fulltext·2018-07-10
Speculative Buffer Overflows: Attacks and Defenses
[Spectre1.1]Speculative Buffer Overflows: Attacks and Defenses
Vladimir Kiriansky
[email protected]
Carl Waldspurger
[email protected]
[1]
red
changebar
#1
changebar
Bear
SLoth
\"ive
[1] #1
[1] #1
[1] #1
#1
[1]Spectre#1
linenumcolorrgb0.5,0,0.5
myschedulergb0.858, 0.188, 0.478
[c]xleftmargin=16pt
[asm]xleftmargin=16pt
linenumcolor
FancyVerbLine
## Abstract
Practical attacks that exploit speculative execution can leak
confidential information via microarchitectural side channels. The
recently-demonstrated Spectre attacks leverage
speculative loads which circumvent access checks to read
memory-resident secrets, transmitting them to an attacker using
cache timing or other covert communication channels.
We introduce 1.1, a new Spectre-v1 variant that
leverages speculative st
https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2019:1946https://access.redhat.com/errata/RHSA-2020:0174https://cdrdv2.intel.com/v1/dl/getContent/685359https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.netapp.com/advisory/ntap-20180823-0001/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2019:1946https://access.redhat.com/errata/RHSA-2020:0174https://cdrdv2.intel.com/v1/dl/getContent/685359https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.netapp.com/advisory/ntap-20180823-0001/https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2018-07-10
Published