Side-channel attack in Kaby Lake and Intel Skylake - CVE-2018-5407
Published: November 6, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability exists due to due to execution of engine sharing on SMT (e.g.Hyper-Threading) architectures when improper handling of information by the processor. A physical attacker can construct a timing side channel to hijack information from processes that are running in the same core.
Note: the vulnerability has been dubbed as PortSmash microarchitecture bug.
Affected software
Intel Skylake
Arch Linux
Debian Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
JBoss Core Services
openssl (Alpine package)
openssl (Debian package)
openssl (Ubuntu package)
imgbased (Red Hat package)
ovirt-node-ng (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
rhvm-appliance (Red Hat package)
redhat-virtualization-host (Red Hat package)
OpenSSL
Tivoli Network Manager IP Edition
Storage Defender – Data Protect
Disk Library for mainframe (DLm)
EMC Cloud Tiering Appliance
Red Hat Virtualization Host
Red Hat Virtualization
Node.js
JBoss Enterprise Web Server
PowerVM Hypervisor
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
NetWorker
How to mitigate CVE-2018-5407
openssl (Debian package) - update to 1.1.0j-1~deb9u1
OpenSSL - update to 1.1.0i
openssl (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27, 1.0.2g-1ubuntu4.14, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1
Node.js - addressed in versions 6.15.0, 8.14.0, 10.9
JBoss Enterprise Web Server - update to 5.2.0
PowerVM Hypervisor - update to FW950.60
imgbased (Red Hat package) - update to 1.1.7-0.1.el7ev
Storage Defender – Data Protect - update to 2.0
ovirt-node-ng (Red Hat package) - update to 4.3.0-0.20181213.0.el7ev
redhat-release-virtualization-host (Red Hat package) - update to 4.3-0.5.el7
rhvm-appliance (Red Hat package) - update to 4.3-20190409.0.el7
redhat-virtualization-host (Red Hat package) - update to 4.3-20190409.0.el7_6
Disk Library for mainframe (DLm) - update to 4.5-4.2
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Information disclosure in Intel processors
- Information disclosure in OpenSSL
- Slackware Linux update for openssl
- OpenSUSE Linux update for openssl
- Multiple vulnerabilities in Node.js
- Debian update for openssl
- OpenSUSE Linux update for openssl-1
- Arch Linux update for openssl-1.0
- Arch Linux update for lib32-openssl-1.0
- Ubuntu update for OpenSSL
- Multiple vulnerabilities in IBM AIX
- OpenSUSE Linux update for compat-openssl098
- Debian update for openssl1.0
- OpenSUSE Linux update for nodejs4
- OpenSUSE Linux update for nodejs6
- Amazon Linux AMI update for openssl
- Gentoo update for OpenSSL
- Red Hat update for openssl
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multple vulnerabilities in Red Hat JBoss Web Server
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Side-channel attack in openssl (Alpine package)
- Red Hat Virtualization update for side-channel attack in SMT processors
- Red Hat Virtualization update for side-channel attack in SMT processors
- Multiple vulnerabilities in Dell EMC Unity Family
- Side-channel attack in Dell EMC Disk Library for mainframe DLm8100 and DLm2100
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Multiple vulnerabilities in IBM Power Systems
- Side-channel attack in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in Dell Networker