Rogue System Register Read in Intel products - CVE-2018-3640
Published: May 22, 2018
Vulnerability identifier: #VU12914
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3640
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists due to race conditions in CPU cache processing. A local attacker can conduct a side-channel attack to exploit a flaw in the speculative loading of system registers to read privileged system registers
Note: the vulnerability is referred to as "Spectre variant 3A".
The weakness exists due to race conditions in CPU cache processing. A local attacker can conduct a side-channel attack to exploit a flaw in the speculative loading of system registers to read privileged system registers
Note: the vulnerability is referred to as "Spectre variant 3A".
Affected software
Intel Atom C3308
Intel Atom Processor E Series
Intel Atom C3958
Intel Atom C3955
Intel Atom C3950
Intel Atom C3858
Intel Atom C3850
Intel Atom C3830
Intel Atom C3808
Intel Atom C3758
Intel Atom C3750
Intel Atom C3708
Intel Atom C3558
Intel Atom C3538
Intel Atom C3508
Intel Atom C3338
Intel Atom Processor A Series
Intel Xeon 7500 series
Intel Xeon 6500 series
Intel Xeon 5600 series
Intel Xeon 5500 series
Intel Xeon 3600 series
Intel Xeon 3400 series
Intel Core M 32nm
Intel Core M 45nm
Intel Core i7 32nm
Intel Core i7 45nm
Intel Core i5 32nm
Intel Core i5 45nm
Intel Core i3 32nm
Intel Core i3 45nm
Intel Atom x5-E3930
Intel Pentium Silver N5000 Processors
Intel Pentium Silver Series J5005
Intel Pentium N4200
Intel Pentium N4100
Intel Celeron N4000 Processors
Intel Celeron J4205
Intel Celeron N3450
Intel Celeron J4105
Intel Celeron J3455
Intel Celeron J3355
Intel Atom Processor Z Series
Intel Atom T5700
Intel Atom T5500
Intel Atom x7-E3950
Intel Atom x5-E3940
Intel Celeron J4005
Intel Xeon E3
Intel Xeon E7
Intel Xeon E5
EMC Isilon OneFS
Debian Linux
VMware ESXi
macOS
Opensuse
vCenter Server
VMware Fusion
VMware Workstation
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
CloudBoost Virtual Appliance
Data Domain Cloud Disaster Recovery
Intel Atom Processor E Series
Intel Atom C3958
Intel Atom C3955
Intel Atom C3950
Intel Atom C3858
Intel Atom C3850
Intel Atom C3830
Intel Atom C3808
Intel Atom C3758
Intel Atom C3750
Intel Atom C3708
Intel Atom C3558
Intel Atom C3538
Intel Atom C3508
Intel Atom C3338
Intel Atom Processor A Series
Intel Xeon 7500 series
Intel Xeon 6500 series
Intel Xeon 5600 series
Intel Xeon 5500 series
Intel Xeon 3600 series
Intel Xeon 3400 series
Intel Core M 32nm
Intel Core M 45nm
Intel Core i7 32nm
Intel Core i7 45nm
Intel Core i5 32nm
Intel Core i5 45nm
Intel Core i3 32nm
Intel Core i3 45nm
Intel Atom x5-E3930
Intel Pentium Silver N5000 Processors
Intel Pentium Silver Series J5005
Intel Pentium N4200
Intel Pentium N4100
Intel Celeron N4000 Processors
Intel Celeron J4205
Intel Celeron N3450
Intel Celeron J4105
Intel Celeron J3455
Intel Celeron J3355
Intel Atom Processor Z Series
Intel Atom T5700
Intel Atom T5500
Intel Atom x7-E3950
Intel Atom x5-E3940
Intel Celeron J4005
Intel Xeon E3
Intel Xeon E7
Intel Xeon E5
EMC Isilon OneFS
Debian Linux
VMware ESXi
macOS
Opensuse
vCenter Server
VMware Fusion
VMware Workstation
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
CloudBoost Virtual Appliance
Data Domain Cloud Disaster Recovery
How to mitigate CVE-2018-3640
The CPU vendors are providing software and firmware updates to mitigate the applicable vulnerabilities to operating system vendors and system manufacturers.
EMC Integrated Data Protection Appliance - update to 2.3
EMC Isilon OneFS - addressed in versions 8.1.0.4, 8.1.2.0
Dell EMC Data Protection Search - update to 18.2
CloudBoost Virtual Appliance - update to 18.2.0.1
Data Domain Cloud Disaster Recovery - update to 18.3 P1
EMC Isilon OneFS - addressed in versions 8.1.0.4, 8.1.2.0
Dell EMC Data Protection Search - update to 18.2
CloudBoost Virtual Appliance - update to 18.2.0.1
Data Domain Cloud Disaster Recovery - update to 18.3 P1
External References
Related Security Bulletins
- Information disclosure in Intel/AMD/ARM CPU
- Information disclosure in VMware products
- OpenSUSE Linux update for ucode-intel
- Debian update for intel-microcode
- openSUSE update for ucode-intel
- Multiple vulnerabilities in Apple MacOS
- Multiple vulnerabilities in Dell EMC CloudBoost Virtual Appliance
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Isilon OneFS
- Multiple vulnerabilities in Dell EMC Data Domain Cloud Disaster Recovery
- Multiple vulnerabilities in Dell EMC Data Protection Search