CVE-2017-5715
MEDIUM5.6EPSS 88.6%linux - security update
Published: 1/4/2018Modified: 11/19/2025
Also known as:ALPINE-CVE-2017-5715DEBIAN-CVE-2017-5715DLA-1422-1
Description
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Affected packages (11)
- Alpine/xenfrom 0, < 4.7.3-r4
- Debian/amd64-microcodefrom 0, < 3.20181128.1~deb8u1
- Debian/amd64-microcodefrom 0, < 3.20180515.1
- Debian/amd64-microcodefrom 0, < 3.20181128.1~deb9u1
- Debian/intel-microcodefrom 0, < 3.20180425.1
- Debian/linuxfrom 0, < 4.15.11-1
- Debian/linuxfrom 0, < 3.16.57-1
- Debian/nvidia-graphics-driversfrom 0, < 384.111-1
- Debian/qemufrom 0, < 1:2.12~rc3+dfsg-1
- Debian/xenfrom 0, < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6
- Debian/xenfrom 0, < 4.11.1~pre+1.733450b39b-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |