CVE-2018-3639
MEDIUM5.5EPSS 46.7%intel-microcode - security update
發布日:2018/5/22修改日:2026/4/28
描述
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
受影響套件(8)
- Alpine/xenfrom 0, < 4.11.0-r0
- Debian/intel-microcodefrom 0, < 3.20180703.2~deb8u1
- Debian/intel-microcodefrom 0, < 3.20180703.1
- Debian/intel-microcodefrom 0, < 3.20180703.2~deb9u1
- Debian/intel-microcodefrom 0, < 3.20180807a.1~deb9u1
- Debian/linuxfrom 0, < 4.16.12-1
- Debian/xenfrom 0, < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u7
- Debian/xenfrom 0, < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |