Side-channel attack in Intel products - CVE-2018-3665

 

Side-channel attack in Intel products - CVE-2018-3665

Published: June 14, 2018 / Updated: June 14, 2018


Vulnerability identifier: #VU13337
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3665
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to utilizing the Lazy FP state restore technique for floating point state when context switching between application processes. A local attacker can conduct cache side-channel attacks and determine register values of other processes.

Note: This vulnerability is known as LazyFP.


Affected software

Intel Core M 32nm
Intel Core M 45nm
Intel Core i7 32nm
Intel Core i7 45nm
Intel Core i5 32nm
Intel Core i5 45nm
Intel Core i3 32nm
Intel Core i3 45nm

Debian Linux
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Real Time
Palo Alto PAN-OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
macOS
SUSE Linux
Opensuse
Fedora
WildFire Appliance (WF-500)
MRG Realtime
kernel (Red Hat package)
kernel-rt (Red Hat package)
xen (Alpine package)
xen
Red Hat Virtualization Host

How to mitigate CVE-2018-3665

Update the affected software.

kernel (Red Hat package) - addressed in versions 2.6.32-754.2.1.el6, 3.10.0-693.47.2.el7, 3.10.0-862.3.3.el7
kernel-rt (Red Hat package) - addressed in versions 3.10.0-693.35.1.rt56.625.el6rt, 3.10.0-693.47.2.rt56.641.el6rt, 3.10.0-862.3.3.rt56.809.el7
xen (Alpine package) - update to 4.7.6-r0
Palo Alto PAN-OS - addressed in versions 8.0.18, 8.1.9
xen - addressed in versions 4.9.2-5.fc27, 4.9.2-6.fc27, 4.10.1-4.fc28

External References

Related Security Bulletins