Wind River Support Network

HomeDefectsLIN1018-4077
Fixed

LIN1018-4077 : Security Advisory - linux - CVE-2018-12130 MFBDS

Created: May 15, 2019    Updated: Jun 16, 2019
Resolved Date: May 24, 2019
Found In Version: 10.18.44.6
Fix Version: 10.18.44.7
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Kernel

Description

https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-12130

CVE-2018-12130 	Microarchitectural Fill Buffer Data Sampling

Under certain conditions, data in microarchitectural structures that the currently-running software does not have permission to access may be speculatively accessed by faulting or assisting load or store operations. This does not result in incorrect program execution because these operations never complete, and their results are never returned to software. However, software may be able to forward this speculative-only data to a side channel disclosure gadget in a way that potentially allows malicious actors to infer the data.


https://www.intel.com/content/www/us/en/architecture-and-technology/mds.html
https://software.intel.com/security-software-guidance/software-guidance/microarchitectural-data-sampling

CVEs


Live chat
Online