Side-channel attack in Intel products - CVE-2018-3615
Published: August 14, 2018 / Updated: August 15, 2018
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in systems with microprocessors utilizing speculative execution and Intel® software guard extensions (Intel® SGX). A local attacker can conduct side-channel attack and gain access to potentially sensitive information residing in the L1 data cache from an enclave.
Affected software
7th Generation Intel Core Processors
6th Generation Intel Core Processors
Intel Xeon Processor E3 v6 Family
Intel Xeon Processor E3 v5 Family
Amazon Linux AMI
Slackware Linux
linux-4.4.153/kernel-generic
linux-4.4.153/kernel-huge
linux-4.4.153/kernel-modules
linux-4.4.153/kernel-headers
CloudBoost Virtual Appliance
How to mitigate CVE-2018-3615
linux-4.4.153/kernel-huge - update to 4.4.153
linux-4.4.153/kernel-modules - update to 4.4.153
linux-4.4.153/kernel-headers - update to 4.4.153_smp
CloudBoost Virtual Appliance - update to 18.2.0.1