MEDIUM · 5.6

CVE-2018-3665

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculati...

Vulnerability Description

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

CVSS Score

5.6

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelCore I3330e
IntelCore I5430m
IntelCore I77y75
IntelCore M5y10
IntelCore M36y30
IntelCore M56y54
IntelCore M76y75
CitrixXenserver7.0
CanonicalUbuntu Linux12.04
DebianDebian Linux8.0
FreebsdFreebsd11.0
RedhatEnterprise Linux6.0
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Workstation6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-3665?

CVE-2018-3665 is a vulnerability with a CVSS score of 5.6 (MEDIUM). System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculati...

How severe is CVE-2018-3665?

CVE-2018-3665 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-3665?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Core I3, Intel Core I5, Intel Core I7, Intel Core M, Intel Core M3.