CVE-2018-3639

Public on 2018-05-22
Modified on 2018-09-15
Description
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent memory write has occurred may see an older value and subsequently cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to read privileged memory by conducting targeted cache side-channel attacks.
Severity
Important severity
Important
CVSS v3 Base Score
5.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 java-1.7.0-openjdk 2018-06-08 ALAS-2018-1037 Fixed
Amazon Linux 2 - Core java-1.7.0-openjdk 2018-06-08 ALAS2-2018-1037 Fixed
Amazon Linux 1 java-1.8.0-openjdk 2018-06-08 ALAS-2018-1039 Fixed
Amazon Linux 2 - Core java-1.8.0-openjdk 2018-06-08 ALAS2-2018-1039 Fixed
Amazon Linux 1 kernel 2018-06-08 ALAS-2018-1038 Fixed
Amazon Linux 2 - Core kernel 2018-06-08 ALAS2-2018-1038 Fixed
Amazon Linux 2 - Core libvirt 2018-06-07 ALAS2-2018-1033 Fixed
Amazon Linux 2 - Core libvirt 2018-07-24 ALAS2-2018-1049 Fixed
Amazon Linux 1 qemu-kvm 2018-06-08 ALAS-2018-1034 Fixed
Amazon Linux 2 - Core qemu-kvm 2018-06-07 ALAS2-2018-1034 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.6 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
NVD CVSSv2 2.1 AV:L/AC:L/Au:N/C:P/I:N/A:N
NVD CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N