VDB

ALPINE-CVE-2018-3639

ALPINE-CVE-2018-3639 PUBLISHED CVSS 5.5 MEDIUM

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Alpine:v3.20xen4.10.0-r2, 4.10.0-r1, 4.10.0-r0
Alpine:v3.23xen4.2.0-r4, 4.10.0-r2, 4.10.0-r1
Alpine:v3.8xen4.2.2-r11, 4.2.2-r11, 4.2.2-r2
Alpine:v3.7xen4.8.1-r4, 4.9.0-r0, 4.9.0-r1
Alpine:v3.6xen4.7.0-r2, 0, 4.0.1-r0
Alpine:v3.15xen0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.14xen4.2.2-r2, 4.2.2-r11, 4.2.2-r10
Alpine:v3.11xen4.5.0-r1, 0, 4.0.1-r1
Alpine:v3.13xen4.2.0-r3, 0, 4.0.1-r0
Alpine:v3.16xen4.9.1-r3, 4.9.1-r2, 4.9.1-r1
Alpine:v3.10xen4.6.0-r4, 4.9.0-r8, 0
Alpine:v3.19xen0, 4.1.2-r10, 4.1.2-r12
Alpine:v3.5xen4.7.3-r8, 4.7.3-r7, 4.7.3-r6
Alpine:v3.21xen4.6.1-r0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.9xen4.0.1-r0, 4.0.1-r1, 4.0.1-r2
Alpine:v3.17xen4.7.1-r2, 0, 4.0.1-r0
Alpine:v3.18xen4.0.1-r0, 4.0.1-r1, 4.0.1-r2
Alpine:v3.22xen4.6.0-r3, 4.9.1-r2, 4.9.1-r1
Alpine:v3.12xen0, 4.0.1-r1, 4.0.1-r2

Timeline

  • May 22, 2018 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›