Description
Description Description
Description Description
Description
VDB

GCP-2025-042

GCP-2025-042 PUBLISHED

<p><strong>Published: </strong>2025-08-11</p><h3 class="hide-from-toc" data-text="Description" id="description_10" tabindex="-1">Description</h3><table> <thead> <tr> <th width="70%">Description</th> <th>Severity</th> <th>Notes</th> </tr> </thead> <tbody> <tr> <td> <p><a href="https://openreview.net/forum?id=4tDNvQe2G0">Researchers</a> discovered a security vulnerability in specific Intel CPUs, including those based on the Skylake, Broadwell, and Haswell microarchitectures. This vulnerability allows an attacker to potentially read sensitive data directly from the CPU's L1 cache that they are not authorized to access.</p> <p>This vulnerability was initially disclosed in <a href="https://nvd.nist.gov/vuln/detail/cve-2018-3646">CVE-2018-3646</a> in 2018. Upon discovery of this vulnerability, Google immediately implemented mitigations that addressed the known risks. Communication regarding the vulnerability and the initial fixes were <a href="https://cloud.google.com/blog/products/gcp/protecting-against-the-new-l1tf-speculative-vulnerabilities">published at that time</a>. Since then we have been researching the residual risk and working with the upstream Linux community to remediate this risk.</p> <p>Recently we worked with security researchers from academia to evaluate the state of the art of CPU security mitigations, and potential attack techniques not considered back in 2018.</p> <p>Google has applied fixes to the affected assets, including Google Cloud, to mitigate the issue.</p> <h4 data-text="What should I do?" id="what-should-i-do_9" tabindex="-1">What should I do?</h4> <p>No customer action is required. Mitigations have already been applied to the Google server fleet.</p> <h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_6" tabindex="-1">What vulnerabilities are being addressed?</h4> <p>For more information, see Intel advisory <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.html">INTEL-SA-00161</a> and CVE-2018-3646.</p> </td> <td>High</td> <td> <a href="https://nvd.nist.gov/vuln/detail/cve-2018-3646">CVE-2018-3646</a> </td> </tr> </tbody> </table>

Timeline

  • Aug 11, 2025 CVE Published
$ Console Community · 100/wk Open console ›