Lucene search

K
redhatcveRedhat.comRH:CVE-2018-3665
HistoryApr 09, 2020 - 7:12 a.m.

CVE-2018-3665

2020-04-0907:12:46
redhat.com
access.redhat.com
32

EPSS

0.001

Percentile

32.0%

A Floating Point Unit (FPU) state information leakage flaw was found in the way the Linux kernel saved and restored the FPU state during task switch. Linux kernels that follow the β€œLazy FPU Restore” scheme are vulnerable to the FPU state information leakage issue. An unprivileged local attacker could use this flaw to read FPU state bits by conducting targeted cache side-channel attacks, similar to the Meltdown vulnerability disclosed earlier this year.

Mitigation

RHEL-7 will automatically default to (safe) β€œeager” floating point register restore on Sandy Bridge and newer Intel processors. AMD processors are not affected. You can mitigate this issue on older processors by booting the kernel with the 'eagerfpu=on' parameter to enable eager FPU restore mode. In this mode FPU state is saved and restored for every task/context switch regardless of whether the current process invokes FPU instructions or not. The parameter does not affect performance negatively, and can be applied with no adverse effects to processors that are not affected.