CVE-2018-12130
Summary
| CVE | CVE-2018-12130 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-30 16:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bugtraq: [SECURITY] [DSA 4469-1] libvirt security update |
BUGTRAQ |
seclists.org |
|
| [SECURITY] Fedora 29 Update: xen-4.11.1-5.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-4602-1 xen |
DEBIAN |
www.debian.org |
|
| FreeBSD-SA-19:26 |
FREEBSD |
security.FreeBSD.org |
|
| INTEL-SA-00233 |
CONFIRM |
www.intel.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [security-announce] openSUSE-SU-2019:1505-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Xen: Multiple vulnerabilities (GLSA 202003-56) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Synology Inc. |
CONFIRM |
www.synology.com |
|
| www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt |
CONFIRM |
www.arubanetworks.com |
|
| McAfee Security Bulletin - Updates for Intel® "ZombieLoad" microprocessor data leakage flaws (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091) |
CONFIRM |
kc.mcafee.com |
|
| cert-portal.siemens.com/productcert/pdf/ssa-616472.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| [security-announce] openSUSE-SU-2019:1805-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| FreeBSD-SA-19:07 |
FREEBSD |
www.freebsd.org |
|
| [SECURITY] [DLA 1789-2] intel-microcode security update |
MLIST |
lists.debian.org |
|
| Bugtraq: FreeBSD Security Advisory FreeBSD-SA-19:26.mcu |
BUGTRAQ |
seclists.org |
|
| cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| USN-3977-3: Intel Microcode update | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| Bugtraq: [SECURITY] [DSA 4564-1] linux security update |
BUGTRAQ |
seclists.org |
|
| FreeBSD Security Advisory - FreeBSD-SA-19:26.mcu ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Bugtraq: [SECURITY] [DSA 4602-1] xen security update |
BUGTRAQ |
seclists.org |
|
| Security Advisory - Intel Microarchitectural Data Sampling (MDS) vulnerabilities |
CONFIRM |
www.huawei.com |
|
| Bugtraq: [SECURITY] [DSA 4447-2] intel-microcode security update |
BUGTRAQ |
seclists.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [security-announce] openSUSE-SU-2019:1806-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| [SECURITY] Fedora 29 Update: xen-4.11.1-5.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296079 Oracle Solaris 11.4 Support Repository Update (SRU) 15.5.0 Missing (CPUOCT2019)
- 377003 Alibaba Cloud Linux Security Update for qemu-kvm (ALINUX2-SA-2019:0030)
- 377032 Alibaba Cloud Linux Security Update for libvirt (ALINUX2-SA-2019:0032)
- 377413 Alibaba Cloud Linux Security Update for virt:rhel and virt-devel:rhel (ALINUX3-SA-2022:0119)
- 378146 Virtuozzo Linux Security Update for libvirt-lock-sanlock (VZLSA-2019:1180)
- 378208 Virtuozzo Linux Security Update for qemu-guest-agent (VZLSA-2019:1181)
- 500752 Alpine Linux Security Update for xen
- 504529 Alpine Linux Security Update for xen
- 590937 Siemens SIMATIC WinAC RTX (F) 2010 Multiple Vulnerabilities (ssa-608355)
- 591420 Siemens ZombieLoad and Microarchitectural Data Sampling Vulnerabilities (SSA-616472)