Back

MEDIUM

hw: cpu: speculative execution permission faults handling

Published Jan 4, 2018

Description

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

Affected products

Remediation

Red Hat statement

Please see the Vulnerability Response article for the full list of updates available and a detailed discussion of this issue. Meltdown patches for 32-bit Red Hat Enterprise Linux 5 ------------------------------------------------------ Red Hat has no current plans to provide mitigations for the Meltdown vulnerability in 32-bit Red Hat Enterprise Linux 5 environments. Following many hours of engineering investigation and analysis, Red Hat has determined that introducing changes to the Red Hat Enterprise Linux 5 environment would destabilize customer deployments and violate our application binary interface (ABI) and kernel ABI commitments to customers who rely on Red Hat Enterprise Linux 5 to be absolutely stable. Although Red Hat has delivered patches to mitigate the Meltdown vulnerability in other supported product offerings, the 32-bit Red Hat Enterprise Linux 5 environment presents unique challenges. The combination of limited address space in 32-bit environments plus the mechanism for passing control from the userspace to kernel and limitations on the stack during this transfer make the projected changes too invasive and disruptive for deployments that require the highest level of system stability. By contrast, 32-bit Meltdown mitigations have been delivered for Red Hat Enterprise Linux 6, where the changes are far less invasive and risky.

References (72)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner intel
Published Jan 4, 2018
Updated May 28, 2026
Reserved Feb 1, 2017
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 3, 2018
ENISA EUVD
Assigner intel
Published Jan 4, 2018
Updated May 28, 2026
Exploited since n/a
EUVD-2017-14831