hw: cpu: speculative execution branch target injection
Published Jan 4, 2018
5.6
MEDIUMCVSS 3.1
EPSS 74.04%
Description
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Affected products
-
- Version AllStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Intel Corporation | Microprocessors with Speculative Execution | n/a |
|
Configuration 1
- c2308
- c2316
- c2338
- c2350
- c2358
- c2508
- c2516
- c2518
- c2530
- c2538
- c2550
- c2558
- c2718
- c2730
- c2738
- c2750
- c2758
- c3308
- c3338
- c3508
- c3538
- c3558
- c3708
- c3750
- c3758
- c3808
- c3830
- c3850
- c3858
- c3950
- c3955
- c3958
- e3805
- e3815
- e3825
- e3826
- e3827
- e3845
- c3130
- c3200rk
- c3205rk
- c3230rk
- c3235rk
- c3265rk
- c3295rk
- c3405
- c3445
- n/a
- n/a
- n/a
- z2420
- z2460
- z2480
- z2520
- z2560
- z2580
- z2760
- z3460
- z3480
- z3530
- z3560
- z3570
- z3580
- z3590
- z3735d
- z3735e
- z3735f
- z3735g
- z3736f
- z3736g
- z3740
- z3740d
- z3745
- z3745d
- z3770
- z3770d
- z3775
- z3775d
- z3785
- z3795
- j1750
- j1800
- j1850
- j1900
- j3060
- j3160
- j3355
- j3455
- j4005
- j4105
- n2805
- n2806
- n2807
- n2808
- n2810
- n2815
- n2820
- n2830
- n2840
- n2910
- n2920
- n2930
- n2940
- n3000
- n3010
- n3050
- n3060
- n3150
- n3160
- n3350
- n3450
- n4000
- n4100
- 330e
- 330m
- 330um
- 350m
- 370m
- 380m
- 380um
- 390m
- 530
- 540
- 550
- 560
- 2100
- 2100t
- 2102
- 2105
- 2115c
- 2120
- 2120t
- 2125
- 2130
- 2310e
- 2310m
- 2312m
- 2328m
- 2330e
- 2330m
- 2340ue
- 2348m
- 2350m
- 2357m
- 2365m
- 2367m
- 2370m
- 2375m
- 2377m
- 3110m
- 3115c
- 3120m
- 3120me
- 3130m
- 3210
- 3217u
- 3217ue
- 3220
- 3220t
- 3225
- 3227u
- 3229y
- 3240
- 3240t
- 3245
- 3250
- 3250t
- 4000m
- 4005u
- 4010u
- 4010y
- 4012y
- 4020y
- 4025u
- 4030u
- 4030y
- 4100e
- 4100m
- 4100u
- 4102e
- 4110e
- 4110m
- 4112e
- 4120u
- 4130
- 4130t
- 4150
- 4150t
- 4158u
- 4160
- 4160t
- 4170
- 4170t
- 4330
- 4330t
- 4330te
- 4340
- 4340te
- 4350
- 4350t
- 4360
- 4360t
- 4370
- 4370t
- 5005u
- 5010u
- 5015u
- 5020u
- 5157u
- 6006u
- 6098p
- 6100
- 6100e
- 6100h
- 6100t
- 6100te
- 6100u
- 6102e
- 6157u
- 6167u
- 6300
- 6300t
- 6320
- 8100
- 8350k
- 430m
- 430um
- 450m
- 460m
- 470um
- 480m
- 520e
- 520m
- 520um
- 540m
- 540um
- 560m
- 560um
- 580m
- 650
- 655k
- 660
- 661
- 670
- 680
- 750
- 750s
- 760
- 2300
- 2310
- 2320
- 2380p
- 2390t
- 2400
- 2400s
- 2405s
- 2410m
- 2430m
- 2435m
- 2450m
- 2450p
- 2467m
- 2500
- 2500k
- 2500s
- 2500t
- 2510e
- 2515e
- 2520m
- 2537m
- 2540m
- 2550k
- 2557m
- 3210m
- 3230m
- 3317u
- 3320m
- 3330
- 3330s
- 3337u
- 3339y
- 3340
- 3340m
- 3340s
- 3350p
- 3360m
- 3380m
- 3427u
- 3437u
- 3439y
- 3450
- 3450s
- 3470
- 3470s
- 3470t
- 3475s
- 3550
- 3550s
- 3570
- 3570k
- 3570s
- 3570t
- 3610me
- 4200h
- 4200m
- 4200u
- 4200y
- 4202y
- 4210h
- 4210m
- 4210u
- 4210y
- 4220y
- 4250u
- 4258u
- 4260u
- 4278u
- 4288u
- 4300m
- 4300u
- 4300y
- 4302y
- 4308u
- 4310m
- 4310u
- 4330m
- 4340m
- 4350u
- 4360u
- 4400e
- 4402e
- 4402ec
- 4410e
- 4422e
- 4430
- 4430s
- 4440
- 4440s
- 4460
- 4460s
- 4460t
- 4570
- 4570r
- 4570s
- 4570t
- 4570te
- 4590
- 4590s
- 4590t
- 4670
- 4670k
- 4670r
- 4670s
- 4670t
- 4690
- 4690k
- 4690s
- 4690t
- 5200u
- 5250u
- 5257u
- 5287u
- 5300u
- 5350h
- 5350u
- 5575r
- 5675c
- 5675r
- 6200u
- 6260u
- 6267u
- 6287u
- 6300hq
- 6300u
- 6350hq
- 6360u
- 6400
- 6400t
- 6402p
- 6440eq
- 6440hq
- 6442eq
- 6500
- 6500t
- 6500te
- 6585r
- 6600
- 6600k
- 6600t
- 6685r
- 8250u
- 8350u
- 8400
- 8600k
- 7y75
- 610e
- 620le
- 620lm
- 620m
- 620ue
- 620um
- 640lm
- 640m
- 640um
- 660lm
- 660ue
- 660um
- 680um
- 720qm
- 740qm
- 820qm
- 840qm
- 860
- 860s
- 870
- 870s
- 875k
- 880
- 920
- 920xm
- 930
- 940
- 940xm
- 950
- 960
- 965
- 970
- 975
- 980
- 980x
- 990x
- 2600
- 2600k
- 2600s
- 2610ue
- 2617m
- 2620m
- 2629m
- 2630qm
- 2635qm
- 2637m
- 2640m
- 2649m
- 2655le
- 2657m
- 2670qm
- 2675qm
- 2677m
- 2700k
- 2710qe
- 2715qe
- 2720qm
- 2760qm
- 2820qm
- 2860qm
- 2920xm
- 2960xm
- 3517u
- 3517ue
- 3520m
- 3537u
- 3540m
- 3555le
- 3610qe
- 3610qm
- 3612qe
- 3612qm
- 3615qe
- 3615qm
- 3630qm
- 3632qm
- 3635qm
- 3667u
- 3687u
- 3689y
- 3720qm
- 3740qm
- 3770
- 3770k
- 3770s
- 3770t
- 3820qm
- 3840qm
- 4500u
- 4510u
- 4550u
- 4558u
- 4578u
- 4600m
- 4600u
- 4610m
- 4610y
- 4650u
- 4700ec
- 4700eq
- 4700hq
- 4700mq
- 4702ec
- 4702hq
- 4702mq
- 4710hq
- 4710mq
- 4712hq
- 4712mq
- 4720hq
- 4722hq
- 4750hq
- 4760hq
- 4765t
- 4770
- 4770hq
- 4770k
- 4770r
- 4770s
- 4770t
- 4770te
- 4771
- 4785t
- 4790
- 4790k
- 4790s
- 4790t
- 4800mq
- 4810mq
- 4850hq
- 4860hq
- 4870hq
- 4900mq
- 4910mq
- 4950hq
- 4960hq
- 4980hq
- 5500u
- 5550u
- 5557u
- 5600u
- 5650u
- 5700eq
- 5700hq
- 5750hq
- 5775c
- 5775r
- 5850eq
- 5850hq
- 5950hq
- 7500u
- 7560u
- 7567u
- 7600u
- 7660u
- 7700
- 7700hq
- 7700k
- 7700t
- 7820eq
- 7820hk
- 7820hq
- 7920hq
- 8550u
- 8650u
- 8700
- 8700k
- 5y10
- 5y10a
- 5y10c
- 5y31
- 5y51
- 5y70
- 5y71
- 6y30
- 7y30
- 7y32
- 6y54
- 6y57
- 6y75
- j2850
- j2900
- j3710
- j4205
- n3510
- n3520
- n3530
- n3540
- n3700
- n3710
- n4200
- e5502
- e5503
- e5504
- e5506
- e5507
- e5520
- e5530
- e5540
- e5603
- e5606
- e5607
- e5620
- e5630
- e5640
- e5645
- e5649
- e6510
- e6540
- e7520
- e7530
- e7540
- ec5509
- ec5539
- ec5549
- l3406
- l3426
- l5506
- l5508
- l5518
- l5520
- l5530
- l5609
- l5618
- l5630
- l5638
- l5640
- l7545
- l7555
- lc5518
- lc5528
- w3670
- w3680
- w3690
- w5580
- w5590
- x3430
- x3440
- x3450
- x3460
- x3470
- x3480
- x5550
- x5560
- x5570
- x5647
- x5650
- x5660
- x5667
- x5670
- x5672
- x5675
- x5677
- x5680
- x5687
- x5690
- x6550
- x7542
- x7550
- x7560
- n/a
- n/a
- n/a
- 1505m_v6
- 1515m_v5
- 1535m_v5
- 1535m_v6
- 1545m_v5
- 1558l_v5
- 1565l_v5
- 1575m_v5
- 1578l_v5
- 1585_v5
- 1585l_v5
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- 2650l_v4
- 2658
- 2658_v2
- 2658_v3
- 2658_v4
- 2658a_v3
- 2660
- 2660_v2
- 2660_v3
- 2660_v4
- 2665
- 2667
- 2667_v2
- 2667_v3
- 2667_v4
- 2670
- 2670_v2
- 2670_v3
- 2680
- 2680_v2
- 2680_v3
- 2680_v4
- 2683_v3
- 2683_v4
- 2687w
- 2687w_v2
- 2687w_v3
- 2687w_v4
- 2690
- 2690_v2
- 2690_v3
- 2690_v4
- 2695_v2
- 2695_v3
- 2695_v4
- 2697_v2
- 2697_v3
- 2697_v4
- 2697a_v4
- 2698_v3
- 2698_v4
- 2699_v3
- 2699_v4
- 2699a_v4
- 2699r_v4
- 4603
- 4603_v2
- 4607
- 4607_v2
- 4610
- 4610_v2
- 4610_v3
- 4610_v4
- 4617
- 4620
- 4620_v2
- 4620_v3
- 4620_v4
- 4624l_v2
- 4627_v2
- 4627_v3
- 4627_v4
- 4628l_v4
- 4640
- 4640_v2
- 4640_v3
- 4640_v4
- 4648_v3
- 4650
- 4650_v2
- 4650_v3
- 4650_v4
- 4650l
- 4655_v3
- 4655_v4
- 4657l_v2
- 4660_v3
- 4660_v4
- 4667_v3
- 4667_v4
- 4669_v3
- 4669_v4
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- 2803
- 2820
- 2830
- 2850
- 2850_v2
- 2860
- 2870
- 2870_v2
- 2880_v2
- 2890_v2
- 4807
- 4809_v2
- 4809_v3
- 4809_v4
- 4820
- 4820_v2
- 4820_v3
- 4820_v4
- 4830
- 4830_v2
- 4830_v3
- 4830_v4
- 4850
- 4850_v2
- 4850_v3
- 4850_v4
- 4860
- 4860_v2
- 4870
- 4870_v2
- 4880_v2
- 4890_v2
- 8830
- 8837
- 8850
- 8850_v2
- 8857_v2
- 8860
- 8860_v3
- 8860_v4
- 8867_v3
- 8867_v4
- 8867l
- 8870
- 8870_v2
- 8870_v3
- 8870_v4
- 8880_v2
- 8880_v3
- 8880_v4
- 8880l_v2
- 8880l_v3
- 8890_v2
- 8890_v3
- 8890_v4
- 8891_v2
- 8891_v3
- 8891_v4
- 8893_v2
- 8893_v3
- 8893_v4
- 8894_v4
- 5115
- 5118
- 5119t
- 5120
- 5120t
- 5122
- 6126
- 6126f
- 6126t
- 6128
- 6130
- 6130f
- 6130t
- 6132
- 6134
- 6134m
- 6136
- 6138
- 6138f
- 6138t
- 6140
- 6140m
- 6142
- 6142f
- 6142m
- 6144
- 6146
- 6148
- 6148f
- 6150
- 6152
- 6154
- 7210
- 7210f
- 7230
- 7230f
- 7235
- 7250
- 7250f
- 7285
- 7290
- 7290f
- 7295
- 8153
- 8156
- 8158
- 8160
- 8160f
- 8160m
- 8160t
- 8164
- 8168
- 8170
- 8170m
- 8176
- 8176f
- 8176m
- 8180
- 4108
- 4109t
- 4110
- 4112
- 4114
- 4114t
- 4116
- 4116t
Configuration 2
Configuration 3
- 12.04
- 14.04
- 16.04
- 17.04
- 17.10
- 18.04
Configuration 4
- n/a
- n/a
- n/a
Configuration 5
- 2010
- 2010
- 2010
Running on/with
- n/a
Configuration 6
- 7.0
- 8.0
- 9.0
Configuration 7
- 8.0.0
- 8.1
- 8.2
- 8.3
- < 5.1.32
- ≥ 5.2.0 · < 5.2.6
No data.
RHEV 3.X Hypervisor and Agents for RHEL-7 ELS
qemu-kvm-rhev-10:2.6.0-28.el7_3.15
Fixed · RHSA-2018:0028
Red Hat Enterprise Linux 5 Extended Lifecycle Support
kernel-0:2.6.18-430.el5
Fixed · RHSA-2018:1196
Red Hat Enterprise Linux 5.9 Long Life
kernel-0:2.6.18-348.39.1.el5
Fixed · RHSA-2018:1252
Red Hat Enterprise Linux 6
kernel-0:2.6.32-696.28.1.el6
Fixed · RHSA-2018:1319
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.76.2.el6
Fixed · RHSA-2018:0020
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.84.2.el6
Fixed · RHSA-2018:0018
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.85.2.el6
Fixed · RHSA-2018:0022
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.64.4.el6
Fixed · RHSA-2018:0017
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
kernel-0:2.6.32-504.64.4.el6
Fixed · RHSA-2018:0017
Red Hat Enterprise Linux 6.7 Extended Update Support
kernel-0:2.6.32-573.55.2.el6
Fixed · RHSA-2018:1346
Red Hat Enterprise Linux 7
dracut-0:033-502.el7_4.1
Fixed · RHBA-2018:0042
Red Hat Enterprise Linux 7
kernel-0:3.10.0-862.el7
Fixed · RHSA-2018:1062
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-49.8.1.el7a
Fixed · RHSA-2018:1967
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-693.11.1.rt56.639.el7
Fixed · RHSA-2018:0016
Red Hat Enterprise Linux 7
libvirt-0:3.9.0-14.el7
Fixed · RHEA-2018:0704
Red Hat Enterprise Linux 7
linux-firmware-0:20180220-62.git6d51311.el7
Fixed · RHEA-2018:0874
Red Hat Enterprise Linux 7
microcode_ctl-2:2.1-29.el7
Fixed · RHEA-2018:0690
Red Hat Enterprise Linux 7
qemu-kvm-10:1.5.3-141.el7_4.6
Fixed · RHSA-2018:0023
Red Hat Enterprise Linux 7
qemu-kvm-ma-10:2.10.0-21.el7
Fixed · RHBA-2018:0831
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.66.1.el7
Fixed · RHSA-2018:1216
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.66.1.el7
Fixed · RHSA-2018:1216
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.66.1.el7
Fixed · RHSA-2018:1216
Red Hat Enterprise Linux 7.3 Extended Update Support
kernel-0:3.10.0-514.48.1.el7
Fixed · RHSA-2018:1129
Red Hat Enterprise Linux 7.3 Extended Update Support
qemu-kvm-10:1.5.3-126.el7_3.13
Fixed · RHSA-2018:0027
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.25.2.el7
Fixed · RHSA-2018:1130
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.11.1.rt56.606.el6rt
Fixed · RHSA-2018:0021
Red Hat Enterprise Linux 5
microcode_ctl
Affected
Red Hat Enterprise Linux 6
libvirt
Affected
Red Hat Enterprise Linux 6
microcode_ctl
Affected
Red Hat Enterprise Linux 6
qemu-kvm
Affected
Red Hat Enterprise Linux 6
qemu-kvm-rhev
Affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
qemu-kvm-rhev
Affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
qemu-kvm-rhev
Affected
Red Hat Enterprise Virtualization 3
rhev-hypervisor
Affected
Red Hat Enterprise Virtualization 3
rhev-hypervisor-ng
Affected
Red Hat Enterprise Virtualization 3
rhevm-setup-plugins
Affected
Red Hat Enterprise Virtualization 3
vdsm
Affected
Red Hat OpenStack Platform 10 (Newton)
qemu-kvm-rhev
Affected
Red Hat OpenStack Platform 11 (Ocata)
qemu-kvm-rhev
Affected
Red Hat OpenStack Platform 12 (Pike)
qemu-kvm-rhev
Affected
Red Hat OpenStack Platform 8 (Liberty)
qemu-kvm-rhev
Affected
Red Hat OpenStack Platform 9 (Mitaka)
qemu-kvm-rhev
Affected
Red Hat Virtualization 4
ovirt-guest-agent-docker
Affected
Red Hat Virtualization 4
redhat-virtualization-host
Affected
Red Hat Virtualization 4
rhevm-appliance
Affected
Red Hat Virtualization 4
rhevm-setup-plugins
Affected
Red Hat Virtualization 4
vdsm
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV 3.X Hypervisor and Agents for RHEL-7 ELS | qemu-kvm-rhev-10:2.6.0-28.el7_3.15 | Fixed | RHSA-2018:0028 |
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | kernel-0:2.6.18-430.el5 | Fixed | RHSA-2018:1196 |
| Red Hat Enterprise Linux 5.9 Long Life | kernel-0:2.6.18-348.39.1.el5 | Fixed | RHSA-2018:1252 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-696.28.1.el6 | Fixed | RHSA-2018:1319 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.76.2.el6 | Fixed | RHSA-2018:0020 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.84.2.el6 | Fixed | RHSA-2018:0018 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.85.2.el6 | Fixed | RHSA-2018:0022 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.64.4.el6 | Fixed | RHSA-2018:0017 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | kernel-0:2.6.32-504.64.4.el6 | Fixed | RHSA-2018:0017 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | kernel-0:2.6.32-573.55.2.el6 | Fixed | RHSA-2018:1346 |
| Red Hat Enterprise Linux 7 | dracut-0:033-502.el7_4.1 | Fixed | RHBA-2018:0042 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-862.el7 | Fixed | RHSA-2018:1062 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-49.8.1.el7a | Fixed | RHSA-2018:1967 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-693.11.1.rt56.639.el7 | Fixed | RHSA-2018:0016 |
| Red Hat Enterprise Linux 7 | libvirt-0:3.9.0-14.el7 | Fixed | RHEA-2018:0704 |
| Red Hat Enterprise Linux 7 | linux-firmware-0:20180220-62.git6d51311.el7 | Fixed | RHEA-2018:0874 |
| Red Hat Enterprise Linux 7 | microcode_ctl-2:2.1-29.el7 | Fixed | RHEA-2018:0690 |
| Red Hat Enterprise Linux 7 | qemu-kvm-10:1.5.3-141.el7_4.6 | Fixed | RHSA-2018:0023 |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma-10:2.10.0-21.el7 | Fixed | RHBA-2018:0831 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.66.1.el7 | Fixed | RHSA-2018:1216 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.66.1.el7 | Fixed | RHSA-2018:1216 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.66.1.el7 | Fixed | RHSA-2018:1216 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | kernel-0:3.10.0-514.48.1.el7 | Fixed | RHSA-2018:1129 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | qemu-kvm-10:1.5.3-126.el7_3.13 | Fixed | RHSA-2018:0027 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.25.2.el7 | Fixed | RHSA-2018:1130 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.11.1.rt56.606.el6rt | Fixed | RHSA-2018:0021 |
| Red Hat Enterprise Linux 5 | microcode_ctl | Affected | n/a |
| Red Hat Enterprise Linux 6 | libvirt | Affected | n/a |
| Red Hat Enterprise Linux 6 | microcode_ctl | Affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm | Affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm-rhev | Affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | qemu-kvm-rhev | Affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | qemu-kvm-rhev | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhev-hypervisor | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhev-hypervisor-ng | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhevm-setup-plugins | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | vdsm | Affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Affected | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | qemu-kvm-rhev | Affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) | qemu-kvm-rhev | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | qemu-kvm-rhev | Affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | qemu-kvm-rhev | Affected | n/a |
| Red Hat Virtualization 4 | ovirt-guest-agent-docker | Affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Affected | n/a |
| Red Hat Virtualization 4 | rhevm-appliance | Affected | n/a |
| Red Hat Virtualization 4 | rhevm-setup-plugins | Affected | n/a |
| Red Hat Virtualization 4 | vdsm | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Please see the Vulnerability Response article for the full list of updates available and a detailed discussion of this issue.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
AV:L/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 74.04% (0.74041) | 99.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 74.04% (0.74041) | 99.42th | v5 (v2026.06.15) |
| Jan 18, 2026 | 88.90% (0.88901) | 99.50th | v4 (v2025.03.14) |
| Jun 17, 2025 | 91.26% (0.91259) | 99.62th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.18% (0.90181) | 99.58th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.52% (0.97515) | 99.99th | v3 (v2023.03.01) |
| Dec 15, 2023 | 97.52% (0.97515) | 99.98th | v3 (v2023.03.01) |
| Jul 15, 2023 | 97.55% (0.97549) | 99.99th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.48% (0.97485) | 99.95th | v3 (v2023.03.01) |
| May 8, 2023 | 97.55% (0.97546) | 99.99th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.58% (0.97581) | 100.00th | v3 (v2023.03.01) |
| Mar 6, 2023 | 74.94% (0.74940) | 99.33th | v2 (v2022.01.01) |
| Oct 1, 2022 | 74.94% (0.74940) | 99.29th | v2 (v2022.01.01) |
| Jun 12, 2022 | 76.93% (0.76928) | 99.35th | v2 (v2022.01.01) |
| Mar 13, 2022 | 82.65% (0.82652) | 99.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 87.48% (0.87485) | 99.71th | v2 (v2022.01.01) |
| Feb 3, 2022 | 46.13% (0.46126) | 98.88th | v1 |
| Sep 1, 2021 | 46.13% (0.46126) | 99.50th | v1 |
| Aug 16, 2021 | 46.13% (0.46126) | 0.00th | v1 |
| Apr 14, 2021 | 45.86% (0.45862) | 0.00th | v1 |
References (99)
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html vendor-advisoryx_refsource_SUSEBroken Link
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609 x_refsource_CONFIRMThird Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611 x_refsource_CONFIRMThird Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613 x_refsource_CONFIRMThird Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614 x_refsource_CONFIRMThird Party Advisory
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt x_refsource_CONFIRMThird Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt x_refsource_CONFIRMThird Party Advisory
- http://www.kb.cert.org/vuls/id/584653 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/102376 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040071 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://xenbits.xen.org/xsa/advisory-254.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0292 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-5715 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/speculativeexecution x_refsource_CONFIRMThird Party Advisory
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ x_refsource_CONFIRMThird Party Advisory
- https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1519780 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf x_refsource_CONFIRMThird Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2018-002 x_refsource_CONFIRMThird Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2018-003 x_refsource_CONFIRMThird Party Advisory
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability x_refsource_CONFIRMThird Party Advisory
- https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html x_refsource_MISCThird Party Advisory
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00025.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00019.html mailing-listx_refsource_MLIST
- https://meltdownattack.com
- https://nvd.nist.gov/vuln/detail/CVE-2017-5715
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 x_refsource_CONFIRMPatchThird Party AdvisoryVendor Advisory
- https://seclists.org/bugtraq/2019/Jun/36 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Nov/16 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr x_refsource_CONFIRMVendor Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.asc vendor-advisoryx_refsource_FREEBSDThird Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:26.mcu.asc vendor-advisoryx_refsource_FREEBSDThird Party Advisory
- https://security.gentoo.org/glsa/201810-06 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html x_refsource_MISCThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180104-0001/ x_refsource_CONFIRMThird Party Advisory
- https://security.paloaltonetworks.com/CVE-2017-5715 x_refsource_CONFIRMThird Party Advisory
- https://spectreattack.com/ x_refsource_MISCThird Party Advisory
- https://support.citrix.com/article/CTX231399 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K91229003 x_refsource_CONFIRMThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us x_refsource_CONFIRMThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us x_refsource_CONFIRMThird Party Advisory
- https://support.lenovo.com/us/en/solutions/LEN-18282 x_refsource_CONFIRMThird Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel vendor-advisoryx_refsource_CISCOThird Party Advisory
- https://usn.ubuntu.com/3531-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3531-3/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3540-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3541-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3542-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3549-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3560-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3561-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3580-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3581-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3581-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3582-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3582-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3594-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3597-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3597-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3620-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3690-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3777-3/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/usn/usn-3516-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-5715
- https://www.debian.org/security/2018/dsa-4120 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2018/dsa-4187 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2018/dsa-4188 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2018/dsa-4213 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.exploit-db.com/exploits/43427/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/180049 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 x_refsource_CONFIRMThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISCThird Party Advisory
- https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ x_refsource_CONFIRMThird Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_01 x_refsource_CONFIRMThird Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2018-0007.html x_refsource_CONFIRMThird Party Advisory
- https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html x_refsource_CONFIRMThird Party Advisory
- https://www.vmware.com/us/security/advisories/VMSA-2018-0004.html x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.