CVE-2018-3620

MEDIUM

Intel Core i3 - Information Disclosure via L1 Data Cache Side-Channel Analysis

Title source: llm
STIX 2.1

Description

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

References (53)

Core 53
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/982149
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041451
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201810-06
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3741-2/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2393
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3823-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2389
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2390
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2403
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105080
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2395
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2384
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3740-2/
Third Party Advisory vendor-advisory x_refsource_freebsd
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:09.l1tf.asc
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4274
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2388
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3741-1/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2603
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2402
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3742-2/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2404
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3740-1/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2391
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2396
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4279
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2392
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/08/msg00029.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3742-1/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2602
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2394
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2387
Third Party Advisory x_refsource_confirm
http://xenbits.xen.org/xsa/advisory-273.html
Technical Description, Third Party Advisory x_refsource_misc
https://foreshadowattack.eu/
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2018-0021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180815-0001/
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K95275140
Third Party Advisory x_refsource_confirm
http://support.lenovo.com/us/en/solutions/LEN-24163
Third Party Advisory x_refsource_confirm
https://www.synology.com/support/security/Synology_SA_18_45
Third Party Advisory x_refsource_confirm
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0009

Scores

CVSS v3 5.6
EPSS 0.0226
EPSS Percentile 84.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (50)
intel/core_i3 330e
intel/core_i3 330m
intel/core_i3 330um
intel/core_i3 350m
intel/core_i3 370m
intel/core_i3 380m
intel/core_i3 380um
intel/core_i3 390m
intel/core_i3 530
intel/core_i3 540
... and 40 more
Published Aug 14, 2018
Tracked Since Feb 18, 2026