[FREEBSD:2310B814-A652-11E8-805B-A4BADB2F4699] FreeBSD -- L1 Terminal Fault (L1TF) Kernel Information Disclosure

Severity Medium
Affected Packages 1
CVEs 2

Problem Description:
On certain Intel 64-bit x86 systems there is a period
of time during terminal fault handling where the CPU may
use speculative execution to try to load data. The CPU may
speculatively access the level 1 data cache (L1D). Data
which would otherwise be protected may then be determined
by using side channel methods.
This issue affects bhyve on FreeBSD/amd64 systems.
Impact:
An attacker executing user code, or kernel code inside
of a virtual machine, may be able to read secret data from
the kernel or from another virtual machine.

Package Affected Version
pkg:freebsd/FreeBSD-kernel < 11.2_2
ID
FREEBSD:2310B814-A652-11E8-805B-A4BADB2F4699
Severity
medium
Severity from
CVE-2018-3620
URL
http://vuxml.freebsd.org/freebsd/2310b814-a652-11e8-805b-a4badb2f4699.html
Published
2018-08-14T00:00:00
(6 years ago)
Modified
2018-08-22T00:00:00
(6 years ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/FreeBSD-kernel FreeBSD-kernel < 11.2_2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...