4.7 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:C/I:N/A:N
5.6 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
0.001 Low
EPSS
Percentile
32.2%
System software utilizing Lazy FP state restore technique on systems using
Intel Core-based microprocessors may potentially allow a local process to
infer data from another process through a speculative execution side
channel.
Author | Note |
---|---|
tyhicks | Xenial and Trusty are affected when running on older x86 processors that do not have support for the xsaveopt instruction. You can verify if your system has support for xsaveopt by locating the âxsaveoptâ feature listed in the flags section of the /proc/cpuinfo file. Precise is affected on all x86 processors. |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 14.04 | noarch | linux | <Â 3.13.0-153.203 | UNKNOWN |
ubuntu | 16.04 | noarch | linux | <Â 4.4.0-130.156 | UNKNOWN |
ubuntu | 14.04 | noarch | linux-aws | <Â 4.4.0-1024.25 | UNKNOWN |
ubuntu | 16.04 | noarch | linux-aws | <Â 4.4.0-1062.71 | UNKNOWN |
ubuntu | 18.04 | noarch | linux-hwe-edge | <Â 4.18.0-8.9~18.04.1 | UNKNOWN |
ubuntu | 16.04 | noarch | linux-kvm | <Â 4.4.0-1029.34 | UNKNOWN |
ubuntu | 14.04 | noarch | linux-lts-xenial | <Â 4.4.0-130.156~14.04.1 | UNKNOWN |
launchpad.net/bugs/cve/CVE-2018-3665
nvd.nist.gov/vuln/detail/CVE-2018-3665
security-tracker.debian.org/tracker/CVE-2018-3665
ubuntu.com/security/notices/USN-3696-1
ubuntu.com/security/notices/USN-3696-2
ubuntu.com/security/notices/USN-3698-1
ubuntu.com/security/notices/USN-3698-2
www.cve.org/CVERecord?id=CVE-2018-3665
www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.html
4.7 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:C/I:N/A:N
5.6 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
0.001 Low
EPSS
Percentile
32.2%