PT-2018-1002 · Intel+13 · Intel Processors+15

Jann Horn

·

Publicado

2018-01-03

·

Atualizado

2026-03-06

·

CVE-2017-5715

CVSS v3.1

5.6

Média

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intel processors (affected versions not specified) ARM processors (affected versions not specified) AMD processors (affected versions not specified)
Description The issue is related to the speculative execution and indirect branch prediction mechanisms in modern processors. It allows an attacker with local user access to potentially disclose information from protected memory by exploiting the side-channel analysis vulnerability. This can lead to information disclosure across trusted boundaries. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited.
Technical details about exploitation include the use of the Indirect Branch Predictor (IBP) and Branch Target Buffer (BTB) components to bypass existing protection and compromise security. The iBranch Locator tool can be used to detect indirect branches and perform targeted injections. The vulnerability can be exploited through the API Endpoints and Vulnerable Parameters or Variables are not explicitly mentioned.
Recommendations For Intel processors, consider using more aggressive indirect branch prediction barriers and strengthening the branch predictor block construction, including more complex tags, encryption, and randomization. For ARM processors, consider implementing similar measures to those for Intel processors to mitigate the vulnerability. For AMD processors, consider implementing similar measures to those for Intel processors to mitigate the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the speculative execution feature until a patch is available. Restrict access to sensitive memory areas to minimize the risk of exploitation. Avoid using vulnerable code paths in the affected processors until the issue is resolved.

Exploit

Information Disclosure

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2022:1988
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2018-1001
ALT-PU-2018-1002
ALT-PU-2018-1023
ALT-PU-2018-1025
ALT-PU-2018-1111
ALT-PU-2018-1112
ALT-PU-2018-1124
ALT-PU-2018-1226
ALT-PU-2018-1253
ALT-PU-2018-1611
ALT-PU-2018-2044
ALT-PU-2018-2045
ALT-PU-2018-2046
ALT-PU-2018-2448
BDU:2018-00003
CESA-2018_0023
CESA-2018_0512
CESA-2018_1062
CESA-2018_1319
CVE-2017-5715
DLA-1369-1
DLA-1422-1
DLA-1422-2
DLA-1497-1
DLA-1506-1
DLA-2148-1
DLA-2323-1
DLA-2743-1
DLA-2743-2
DSA-4120-1
DSA-4120-2
DSA-4179-1
DSA-4187-1
DSA-4188-1
DSA-4201-1
DSA-4213-1
DSA-4469-1
ELSA-2018-0007
ELSA-2018-0008
ELSA-2018-0023
ELSA-2018-0024
ELSA-2018-0029
ELSA-2018-0030
ELSA-2018-4004
ELSA-2018-4020
ELSA-2018-4022
ELSA-2018-4285
ELSA-2018-4289
ELSA-2019-4710
ELSA-2019-4785
FREEBSD-SA-18_03
MGASA-2018-0073
MGASA-2018-0074
MGASA-2018-0076
MGASA-2018-0077
MGASA-2018-0079
MGASA-2018-0080
MGASA-2018-0082
MGASA-2018-0101
MGASA-2018-0106
MGASA-2018-0107
MGASA-2018-0124
MGASA-2018-0125
MGASA-2018-0126
MGASA-2018-0127
MGASA-2018-0134
MGASA-2018-0153
MGASA-2018-0172
MGASA-2018-0176
MGASA-2018-0260
OPENSUSE-SU-2018_0013-1
OPENSUSE-SU-2018_0022-1
OPENSUSE-SU-2018_0023-1
OPENSUSE-SU-2018_0026-1
OPENSUSE-SU-2018_0030-1
OPENSUSE-SU-2018_0059-1
OPENSUSE-SU-2018_0066-1
OPENSUSE-SU-2018_0187-1
OPENSUSE-SU-2018_0326-1
OPENSUSE-SU-2018_0408-1
OPENSUSE-SU-2018_0459-1
OPENSUSE-SU-2018_0710-1
OPENSUSE-SU-2018_0745-1
OPENSUSE-SU-2018_0780-1
OPENSUSE-SU-2018_0939-1
OPENSUSE-SU-2018_1502-1
OPENSUSE-SU-2018_1623-1
OPENSUSE-SU-2018_1631-1
OPENSUSE-SU-2018_2119-1
OPENSUSE-SU-2018_2237-1
OPENSUSE-SU-2018_2524-1
OPENSUSE-SU-2024:10633-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:10894-1
OPENSUSE-SU-2024:11287-1
OPENSUSE-SU-2024:11478-1
OPENSUSE-SU-2024:13704-1
OPENSUSE-SU-2025:14769-1
OPENSUSE-SU-2025:14770-1
OPENSUSE-SU-2025:14771-1
OPENSUSE-SU-2025:14772-1
OPENSUSE-SU-2025:14773-1
OPENSUSE-SU-2025:14774-1
OPENSUSE-SU-2025:14775-1
OPENSUSE-SU-2025:14776-1
OPENSUSE-SU-2025:14777-1
OPENSUSE-SU-2025:14778-1
OPENSUSE-SU-2025:14779-1
OPENSUSE-SU-2025:14780-1
OPENSUSE-SU-2025:14781-1
OPENSUSE-SU-2025:14782-1
OPENSUSE-SU-2025:14783-1
OPENSUSE-SU-2025:14784-1
OPENSUSE-SU-2025:14785-1
OPENSUSE-SU-2025:14786-1
OPENSUSE-SU-2025:14787-1
OPENSUSE-SU-2025:14788-1
OPENSUSE-SU-2025:14789-1
OPENSUSE-SU-2025:14790-1
OPENSUSE-SU-2025:14791-1
OPENSUSE-SU-2025:14792-1
OPENSUSE-SU-2025:14793-1
OPENSUSE-SU-2025:14794-1
OPENSUSE-SU-2025:14795-1
OPENSUSE-SU-2025:14796-1
OPENSUSE-SU-2025:14797-1
OPENSUSE-SU-2025:14798-1
OPENSUSE-SU-2025:14799-1
OPENSUSE-SU-2025:14800-1
OPENSUSE-SU-2025:14801-1
OPENSUSE-SU-2025:14804-1
RHSA-2018:0010
RHSA-2018:0016
RHSA-2018:0017
RHSA-2018:0018
RHSA-2018:0020
RHSA-2018:0021
RHSA-2018:0022
RHSA-2018:0023
RHSA-2018:0151
RHSA-2018:0182
RHSA-2018:0292
RHSA-2018:1062
RHSA-2018:1129
RHSA-2018:1130
RHSA-2018:1196
RHSA-2018:1216
RHSA-2018:1252
RHSA-2018:1319
RHSA-2018:1346
RHSA-2018:1967
RHSA-2018_0016
RHSA-2018_0023
RHSA-2018_1062
RHSA-2018_1196
RHSA-2018_1319
SUSE-RU-2018:0779-1
SUSE-RU-2018:0821-1
SUSE-SU-2018:0007-1
SUSE-SU-2018:0008-1
SUSE-SU-2018:0010-1
SUSE-SU-2018:0011-1
SUSE-SU-2018:0012-1
SUSE-SU-2018:0019-1
SUSE-SU-2018:0020-1
SUSE-SU-2018:0031-1
SUSE-SU-2018:0036-1
SUSE-SU-2018:0039-1
SUSE-SU-2018:0040-1
SUSE-SU-2018:0041-1
SUSE-SU-2018:0051-1
SUSE-SU-2018:0056-1
SUSE-SU-2018:0068-1
SUSE-SU-2018:0069-1
SUSE-SU-2018:0113-1
SUSE-SU-2018:0114-1
SUSE-SU-2018:0115-1
SUSE-SU-2018:0131-1
SUSE-SU-2018:0171-1
SUSE-SU-2018:0180-1
SUSE-SU-2018:0213-1
SUSE-SU-2018:0219-1
SUSE-SU-2018:0285-1
SUSE-SU-2018:0383-1
SUSE-SU-2018:0416-1
SUSE-SU-2018:0437-1
SUSE-SU-2018:0438-1
SUSE-SU-2018:0472-1
SUSE-SU-2018:0482-1
SUSE-SU-2018:0525-1
SUSE-SU-2018:0552-1
SUSE-SU-2018:0552-2
SUSE-SU-2018:0555-1
SUSE-SU-2018:0601-1
SUSE-SU-2018:0609-1
SUSE-SU-2018:0638-1
SUSE-SU-2018:0660-1
SUSE-SU-2018:0678-1
SUSE-SU-2018:0705-1
SUSE-SU-2018:0708-1
SUSE-SU-2018:0757-1
SUSE-SU-2018:0762-1
SUSE-SU-2018:0831-1
SUSE-SU-2018:0838-1
SUSE-SU-2018:0841-1
SUSE-SU-2018:0861-1
SUSE-SU-2018:0909-1
SUSE-SU-2018:0920-1
SUSE-SU-2018:0986-1
SUSE-SU-2018:1077-1
SUSE-SU-2018:1080-1
SUSE-SU-2018:1295-1
SUSE-SU-2018:1308-1
SUSE-SU-2018:1363-1
SUSE-SU-2018:1368-1
SUSE-SU-2018:1376-1
SUSE-SU-2018:1386-1
SUSE-SU-2018:1465-1
SUSE-SU-2018:1486-1
SUSE-SU-2018:1498-1
SUSE-SU-2018:1503-1
SUSE-SU-2018:1567-1
SUSE-SU-2018:1570-1
SUSE-SU-2018:1571-1
SUSE-SU-2018:1571-2
SUSE-SU-2018:1603-1
SUSE-SU-2018:1658-1
SUSE-SU-2018:1699-1
SUSE-SU-2018:1699-2
SUSE-SU-2018:1759-1
SUSE-SU-2018:1784-1
SUSE-SU-2018:1822-1
SUSE-SU-2018:2082-1
SUSE-SU-2018:2092-1
SUSE-SU-2018:2141-1
SUSE-SU-2018:2189-1
SUSE-SU-2018:2528-1
SUSE-SU-2018:2631-1
SUSE-SU-2018:2631-2
SUSE-SU-2018_0006-1
SUSE-SU-2018_0007-1
SUSE-SU-2018_0008-1
SUSE-SU-2018_0009-1
SUSE-SU-2018_0010-1
SUSE-SU-2018_0011-1
SUSE-SU-2018_0012-1
SUSE-SU-2018_0019-1
SUSE-SU-2018_0020-1
SUSE-SU-2018_0031-1
SUSE-SU-2018_0036-1
SUSE-SU-2018_0039-1
SUSE-SU-2018_0041-1
SUSE-SU-2018_0051-1
SUSE-SU-2018_0056-1
SUSE-SU-2018_0067-1
SUSE-SU-2018_0068-1
SUSE-SU-2018_0069-1
SUSE-SU-2018_0113-1
SUSE-SU-2018_0114-1
SUSE-SU-2018_0115-1
SUSE-SU-2018_0171-1
SUSE-SU-2018_0383-1
SUSE-SU-2018_0416-1
SUSE-SU-2018_0438-1
SUSE-SU-2018_0472-1
SUSE-SU-2018_0525-1
SUSE-SU-2018_0555-1
SUSE-SU-2018_0601-1
SUSE-SU-2018_0609-1
SUSE-SU-2018_0638-1
SUSE-SU-2018_0660-1
SUSE-SU-2018_0678-1
SUSE-SU-2018_0705-1
SUSE-SU-2018_0708-1
SUSE-SU-2018_0757-1
SUSE-SU-2018_0762-1
SUSE-SU-2018_0831-1
SUSE-SU-2018_0838-1
SUSE-SU-2018_0861-1
SUSE-SU-2018_0909-1
SUSE-SU-2018_0920-1
SUSE-SU-2018_1077-1
SUSE-SU-2018_1080-1
SUSE-SU-2018_1295-1
SUSE-SU-2018_1308-1
SUSE-SU-2018_1465-1
SUSE-SU-2018_1486-1
SUSE-SU-2018_1498-1
SUSE-SU-2018_1503-1
SUSE-SU-2018_1567-1
SUSE-SU-2018_1570-1
SUSE-SU-2018_1571-1
SUSE-SU-2018_1571-2
SUSE-SU-2018_1759-1
SUSE-SU-2018_1784-1
SUSE-SU-2018_2189-1
SUSE-SU-2018_2631-1
SUSE-SU-2018_2631-2
SUSE-SU-2019:13999-1
SUSE-SU-2019_13999-1
USN-3516-1
USN-3530-1
USN-3531-1
USN-3531-2
USN-3531-3
USN-3540-1
USN-3540-2
USN-3541-1
USN-3541-2
USN-3542-1
USN-3542-2
USN-3549-1
USN-3560-1
USN-3561-1
USN-3580-1
USN-3581-1
USN-3581-2
USN-3582-1
USN-3582-2
USN-3594-1
USN-3597-1
USN-3597-2
USN-3620-2
USN-3690-1
USN-3690-2
USN-3777-3

Produtos afetados

Alt Linux
Amd Processors
Centos
Edge
Freebsd
Huawei Vrp
Ibm Aix
Intel Processors
Internet Explorer
Sql Server
Red Hat
Suse
Ubuntu
Vmware Vcenter
Virtualbox
Windows