Multiple CPU Hardwares CVE-2018-3640 Information Disclosure Vulnerability
BID:104228
CVE-2018-3640 |Info
Multiple CPU Hardwares CVE-2018-3640 Information Disclosure Vulnerability
| Bugtraq ID: | 104228 |
| Class: | Design Error |
| CVE: |
CVE-2018-3640 |
| Remote: | No |
| Local: | Yes |
| Published: | May 21 2018 12:00AM |
| Updated: | May 21 2018 12:00AM |
| Credit: | Jann Horn (Google Project Zero), Werner Haas, Thomas Prescher (Cyberus Technology), Zdenek Sojka, Innokentiy Sennovskiy from BiZone LLC, Rudolf Marek and Alex Zuepke from SYSGO AG |
| Vulnerable: |
Microsoft Surface Studio 0 Microsoft Surface Pro with Advanced LTE Model 1807 0 Microsoft Surface Pro Model 1796 0 Microsoft Surface Pro 4 0 Microsoft Surface Pro 3 0 Microsoft Surface Laptop 0 Microsoft Surface Book 2 Microsoft Surface Book 0 Intel Xeon Processor E7 v4 Family 0 Intel Xeon Processor E7 v3 Family 0 Intel Xeon Processor E7 v2 Family 0 Intel Xeon Processor E7 Family 0 Intel Xeon Processor E5 v4 Family 0 Intel Xeon Processor E5 v3 Family 0 Intel Xeon Processor E5 v2 Family 0 Intel Xeon Processor E5 Family 0 Intel Xeon Processor E3 v6 Family 0 Intel Xeon Processor E3 v5 Family 0 Intel Xeon Processor E3 v4 Family 0 Intel Xeon Processor E3 v3 Family 0 Intel Xeon Processor E3 v2 Family 0 Intel Xeon Processor E3 Family 0 Intel Xeon processor 7500 series 0 Intel Xeon processor 6500 series 0 Intel Xeon processor 5600 series 0 Intel Xeon processor 5500 series 0 Intel Xeon processor 3600 series 0 Intel Xeon processor 3400 series 0 Intel Pentium Processor Silver Series 0 Intel Pentium Processor N Series 0 Intel Pentium Processor J Series 0 Intel Core X-series Processor Family for Intel X99 platforms 0 Intel Core X-series Processor Family for Intel X299 platforms 0 Intel Core M processor family 0 Intel Celeron Processor N Series 0 Intel Celeron Processor J Series 0 Intel Atom Processor Z Series 0 Intel Atom Processor X Series 0 Intel Atom Processor T Series 0 Intel Atom Processor E Series 0 Intel Atom Processor C Series 0 Intel Atom Processor A Series 0 Intel 8th generation Core processors 0 Intel 7th generation Core processors 0 Intel 6th generation Core processors 0 Intel 5th generation Core processors 0 Intel 4th generation Core processors 0 Intel 3rd generation Core processors 0 Intel 2nd generation Core processors 0 ARM Cortex A72 0 ARM Cortex A57 0 |
| Not Vulnerable: | |
Discussion
Exploit / POC
Multiple CPU Hardwares CVE-2018-3640 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple CPU Hardwares CVE-2018-3640 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple CPU Hardwares CVE-2018-3640 Information Disclosure Vulnerability
References:
References:
- AMD Home Page (AMD)
- ARM Homepage (ARM)
- Intel Home Page (Intel)
- ADV180013 | Microsoft Guidance for Rogue System Register Read (Microsoft)
- Alert (TA18-141A) Side-Channel Vulnerability Variants 3a and 4 (CERT)
- Bug 1580340 - (CVE-2018-3640) CVE-2018-3640 hw: cpu: speculative register load (Redhat)
- CPU Side-Channel Information Disclosure Vulnerabilities: May 2018 (Cisco)
- CVE-2018-3640 (Redhat)
- Q2 2018 Speculative Execution Side Channel Update (Intel)
- VMware Response to Speculative Execution security issues, CVE-2018-3639 and CVE- (VMware)
- VU#180049 CPU hardware utilizing speculative execution may be vulnerable to cach (CERT)
- Vulnerability of Speculative Processors to Cache Timing Side-Channel Mechanism (ARM)