CVE-2018-15572 PUBLISHED

The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduct userspace-userspace spectreRSB attacks.

EPSS 0.04% · 12.8th percentile

Risk Scores

EPSS Score
0.04%
12.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-kvm4.15.0-1019.19, 0, 4.15.0-1002.2
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1015.18, 4.4.0-1092.97, 4.4.0-1090.95
Ubuntu:18.04:LTSlinux4.13.0-25.29, 4.13.0-17.20, 4.13.0-16.19
Ubuntu:16.04:LTSlinux-gcp4.10.0-1004.4, 4.13.0-1011.15, 0
Ubuntu:16.04:LTSlinux-raspi20, 4.4.0-1096.104, 4.4.0-1095.103
Ubuntu:16.04:LTSlinux-azure4.13.0-1005.7, 4.13.0-1006.8, 4.13.0-1007.9
Ubuntu:18.04:LTSlinux-aws4.15.0-1001.1, 4.15.0-1006.6, 4.15.0-1007.7
Ubuntu:18.04:LTSlinux-oem4.15.0-1006.9, 4.15.0-1008.11, 4.15.0-1009.12
Ubuntu:16.04:LTSlinux-aws4.4.0-1049.58, 0, 4.4.0-1001.10
Ubuntu:16.04:LTSlinux-hwe4.15.0-30.32~16.04.1, 4.15.0-34.37~16.04.1, 4.15.0-33.36~16.04.1
Ubuntu:18.04:LTSlinux-raspi24.15.0-1022.24, 0, 4.13.0-1005.5
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-21.37~14.04.1, 4.4.0-13.29~14.04.1, 4.4.0-14.30~14.04.2
Ubuntu:16.04:LTSlinux4.4.0-16.32, 4.4.0-15.31, 4.4.0-14.30
Ubuntu:16.04:LTSlinux-kvm4.4.0-1032.38, 0, 4.4.0-1026.31
Ubuntu:14.04:LTSlinux-azure0, 4.15.0-1023.24~14.04.1
Ubuntu:14.04:LTSlinux-aws4.4.0-1019.19, 4.4.0-1029.32, 4.4.0-1028.31
Ubuntu:18.04:LTSlinux-gcp0, 4.15.0-1010.10, 4.15.0-1014.14
Ubuntu:18.04:LTSlinux-azure4.15.0-1008.8, 4.15.0-1004.4, 4.15.0-1021.21

Timeline

References

Open in Interactive Console →