Side-channel attack in Kaby Lake and Intel Skylake - CVE-2018-5407

 

Side-channel attack in Kaby Lake and Intel Skylake - CVE-2018-5407

Published: November 6, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU15723
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5407
CWE-ID: CWE-208
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a physical attacker to obtain potentially sensitive information.

The vulnerability exists due to due to execution of engine sharing on SMT (e.g.Hyper-Threading) architectures when improper handling of information by the processor. A physical attacker can construct a timing side channel to hijack information from processes that are running in the same core.

Note: the vulnerability has been dubbed as PortSmash microarchitecture bug.


Affected software

Kaby Lake
Intel Skylake
Arch Linux
Debian Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
JBoss Core Services
openssl (Alpine package)
openssl (Debian package)
openssl (Ubuntu package)
imgbased (Red Hat package)
ovirt-node-ng (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
rhvm-appliance (Red Hat package)
redhat-virtualization-host (Red Hat package)
OpenSSL
Tivoli Network Manager IP Edition
Storage Defender – Data Protect
Disk Library for mainframe (DLm)
EMC Cloud Tiering Appliance
Red Hat Virtualization Host
Red Hat Virtualization
Node.js
JBoss Enterprise Web Server
PowerVM Hypervisor
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
NetWorker

How to mitigate CVE-2018-5407

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

openssl (Alpine package) - update to 1.0.2q-r0
openssl (Debian package) - update to 1.1.0j-1~deb9u1
OpenSSL - update to 1.1.0i
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27, 1.0.2g-1ubuntu4.14, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1
Node.js - addressed in versions 6.15.0, 8.14.0, 10.9
JBoss Enterprise Web Server - update to 5.2.0
PowerVM Hypervisor - update to FW950.60
imgbased (Red Hat package) - update to 1.1.7-0.1.el7ev
Storage Defender – Data Protect - update to 2.0
ovirt-node-ng (Red Hat package) - update to 4.3.0-0.20181213.0.el7ev
redhat-release-virtualization-host (Red Hat package) - update to 4.3-0.5.el7
rhvm-appliance (Red Hat package) - update to 4.3-20190409.0.el7
redhat-virtualization-host (Red Hat package) - update to 4.3-20190409.0.el7_6
Disk Library for mainframe (DLm) - update to 4.5-4.2
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins