Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis
Published Aug 14, 2018
7.3
HIGHCVSS 3.1
EPSS 6.30%
Description
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
Affected products
-
- Version MultipleStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Intel Corporation | Multiple | n/a |
|
Configuration 1
- 6006u
- 6098p
- 6100
- 6100e
- 6100h
- 6100t
- 6100te
- 6100u
- 6102e
- 6157u
- 6167u
- 6300
- 6300t
- 6320
- 650
- 655k
- 660
- 661
- 670
- 680
- 6200u
- 6260u
- 6267u
- 6287u
- 6300hq
- 6300u
- 6350hq
- 6360u
- 6400
- 6400t
- 6402p
- 6440eq
- 6440hq
- 6442eq
- 6500
- 6500t
- 6500te
- 6585r
- 6600
- 6600k
- 6600t
- 6685r
- 610e
- 620le
- 620lm
- 620m
- 620ue
- 620um
- 640lm
- 640m
- 640um
- 660lm
- 660ue
- 660um
- 680um
Configuration 2
- 750
- 750s
- 760
- 7y75
- 720qm
- 740qm
- 7500u
- 7560u
- 7567u
- 7600u
- 7660u
- 7700
- 7700hq
- 7700k
- 7700t
- 7820eq
- 7820hk
- 7820hq
- 7920hq
Configuration 3
- 8100
- 8350k
- 8250u
- 8350u
- 8400
- 8600k
- 820qm
- 840qm
- 860
- 860s
- 870
- 870s
- 875k
- 880
- 8550u
- 8650u
- 8700
- 8700k
Configuration 4
- 1515m_v5
- 1535m_v5
- 1545m_v5
- 1558l_v5
- 1565l_v5
- 1575m_v5
- 1578l_v5
- 1585_v5
- 1585l_v5
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 5
- 1505m_v6
- 1535m_v6
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of kernel as shipped with any Red Hat product.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
AV:L/AC:M/Au:N/C:C/I:P/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.30% (0.06301) | 93.39th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.30% (0.06301) | 92.68th | v5 (v2026.06.15) |
| Nov 21, 2025 | 1.37% (0.01369) | 79.64th | v4 (v2025.03.14) |
| Nov 18, 2025 | 0.08% (0.00076) | 18.96th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.57% (0.01567) | 79.81th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.23% (0.03225) | 78.27th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.35% (0.01355) | 78.81th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00047) | 19.31th | v3 (v2023.03.01) |
| May 14, 2024 | 0.05% (0.00048) | 17.04th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00048) | 15.03th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.86% (0.01864) | 77.24th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.86% (0.01864) | 77.19th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.86% (0.01864) | 75.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.86% (0.01864) | 54.47th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.45% (0.03449) | 68.31th | v1 |
| Jan 6, 2022 | 3.45% (0.03449) | 68.01th | v1 |
| Sep 1, 2021 | 3.45% (0.03449) | 81.94th | v1 |
| Apr 14, 2021 | 3.45% (0.03449) | 0.00th | v1 |
References (20)
- http://support.lenovo.com/us/en/solutions/LEN-24163 x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-en x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/105080 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041451 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-3615 Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdf x_refsource_CONFIRM
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf x_refsource_CONFIRM
- https://foreshadowattack.eu/ x_refsource_MISCTechnical DescriptionThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-3615
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0008 x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180815-0001/ x_refsource_CONFIRMThird Party Advisory
- https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-fault x_refsource_CONFIRMMitigationVendor Advisory
- https://support.f5.com/csp/article/K35558453 x_refsource_CONFIRMThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_us x_refsource_CONFIRMThird Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannel vendor-advisoryx_refsource_CISCOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-3615
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.html x_refsource_CONFIRMVendor Advisory
- https://www.kb.cert.org/vuls/id/982149 third-party-advisoryx_refsource_CERT-VNThird Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_45 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.