CVE-2018-3639
medium · 5.5Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
5.5
CVSS
60.6%
EPSS (exploit prob.)
99th
EPSS percentile
2018-05-22
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-203
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| intel | atom_c | c2308 |
| intel | atom_c | c3308 |
| intel | atom_c | c3338 |
| intel | atom_c | c3508 |
| intel | atom_c | c3538 |
| intel | atom_c | c3558 |
| intel | atom_c | c3708 |
| intel | atom_c | c3750 |
| intel | atom_c | c3758 |
| intel | atom_c | c3808 |
| intel | atom_c | c3830 |
| intel | atom_c | c3850 |
| intel | atom_c | c3858 |
| intel | atom_c | c3950 |
| intel | atom_c | c3955 |
| intel | atom_c | c3958 |
| intel | atom_e | e3805 |
| intel | atom_e | e3815 |
| intel | atom_e | e3825 |
| intel | atom_e | e3826 |
| intel | atom_e | e3827 |
| intel | atom_e | e3845 |
| intel | atom_x5-e3930 | all versions |
| intel | atom_x5-e3940 | all versions |
| intel | atom_x7-e3950 | all versions |
| intel | atom_z | z2420 |
| intel | atom_z | z2460 |
| intel | atom_z | z2480 |
| intel | atom_z | z2520 |
| intel | atom_z | z2560 |
| intel | atom_z | z2580 |
| intel | atom_z | z2760 |
| intel | atom_z | z3460 |
| intel | atom_z | z3480 |
| intel | atom_z | z3530 |
| intel | atom_z | z3560 |
| intel | atom_z | z3570 |
| intel | atom_z | z3580 |
| intel | atom_z | z3590 |
| intel | atom_z | z3735d |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html
- http://support.lenovo.com/us/en/solutions/LEN-22133
- http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.html
- http://www.openwall.com/lists/oss-security/2020/06/10/1
- http://www.openwall.com/lists/oss-security/2020/06/10/2
- http://www.openwall.com/lists/oss-security/2020/06/10/5
- http://www.securityfocus.com/bid/104232
- http://www.securitytracker.com/id/1040949
- http://www.securitytracker.com/id/1042004
- http://xenbits.xen.org/xsa/advisory-263.html
- https://access.redhat.com/errata/RHSA-2018:1629
- https://access.redhat.com/errata/RHSA-2018:1630
- https://access.redhat.com/errata/RHSA-2018:1632
- https://access.redhat.com/errata/RHSA-2018:1633
- https://access.redhat.com/errata/RHSA-2018:1635
- https://access.redhat.com/errata/RHSA-2018:1636
- https://access.redhat.com/errata/RHSA-2018:1637
- https://access.redhat.com/errata/RHSA-2018:1638
- https://access.redhat.com/errata/RHSA-2018:1639
- https://access.redhat.com/errata/RHSA-2018:1640
- https://access.redhat.com/errata/RHSA-2018:1641
- https://access.redhat.com/errata/RHSA-2018:1642
- https://access.redhat.com/errata/RHSA-2018:1643
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-3639