CVE Vulnerabilities

CVE-2018-3665

Exposure of Sensitive Information to an Unauthorized Actor

Published: Jun 21, 2018 | Modified: Jun 09, 2021
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
4.7 MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

Weakness

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Software

Name Vendor Start Version End Version
Core_i3 Intel 330e (including) 330e (including)
Core_i3 Intel 330m (including) 330m (including)
Core_i3 Intel 330um (including) 330um (including)
Core_i3 Intel 350m (including) 350m (including)
Core_i3 Intel 370m (including) 370m (including)
Core_i3 Intel 380m (including) 380m (including)
Core_i3 Intel 380um (including) 380um (including)
Core_i3 Intel 390m (including) 390m (including)
Core_i3 Intel 530 (including) 530 (including)
Core_i3 Intel 540 (including) 540 (including)
Core_i3 Intel 550 (including) 550 (including)
Core_i3 Intel 560 (including) 560 (including)
Core_i3 Intel 2100 (including) 2100 (including)
Core_i3 Intel 2100t (including) 2100t (including)
Core_i3 Intel 2102 (including) 2102 (including)
Core_i3 Intel 2105 (including) 2105 (including)
Core_i3 Intel 2115c (including) 2115c (including)
Core_i3 Intel 2120 (including) 2120 (including)
Core_i3 Intel 2120t (including) 2120t (including)
Core_i3 Intel 2125 (including) 2125 (including)
Core_i3 Intel 2130 (including) 2130 (including)
Core_i3 Intel 2310e (including) 2310e (including)
Core_i3 Intel 2310m (including) 2310m (including)
Core_i3 Intel 2312m (including) 2312m (including)
Core_i3 Intel 2328m (including) 2328m (including)
Core_i3 Intel 2330e (including) 2330e (including)
Core_i3 Intel 2330m (including) 2330m (including)
Core_i3 Intel 2340ue (including) 2340ue (including)
Core_i3 Intel 2348m (including) 2348m (including)
Core_i3 Intel 2350m (including) 2350m (including)
Core_i3 Intel 2357m (including) 2357m (including)
Core_i3 Intel 2365m (including) 2365m (including)
Core_i3 Intel 2367m (including) 2367m (including)
Core_i3 Intel 2370m (including) 2370m (including)
Core_i3 Intel 2375m (including) 2375m (including)
Core_i3 Intel 2377m (including) 2377m (including)
Core_i3 Intel 3110m (including) 3110m (including)
Core_i3 Intel 3115c (including) 3115c (including)
Core_i3 Intel 3120m (including) 3120m (including)
Core_i3 Intel 3120me (including) 3120me (including)
Core_i3 Intel 3130m (including) 3130m (including)
Core_i3 Intel 3210 (including) 3210 (including)
Core_i3 Intel 3217u (including) 3217u (including)
Core_i3 Intel 3217ue (including) 3217ue (including)
Core_i3 Intel 3220 (including) 3220 (including)
Core_i3 Intel 3220t (including) 3220t (including)
Core_i3 Intel 3225 (including) 3225 (including)
Core_i3 Intel 3227u (including) 3227u (including)
Core_i3 Intel 3229y (including) 3229y (including)
Core_i3 Intel 3240 (including) 3240 (including)
Core_i3 Intel 3240t (including) 3240t (including)
Core_i3 Intel 3245 (including) 3245 (including)
Core_i3 Intel 3250 (including) 3250 (including)
Core_i3 Intel 3250t (including) 3250t (including)
Core_i3 Intel 4000m (including) 4000m (including)
Core_i3 Intel 4005u (including) 4005u (including)
Core_i3 Intel 4010u (including) 4010u (including)
Core_i3 Intel 4010y (including) 4010y (including)
Core_i3 Intel 4012y (including) 4012y (including)
Core_i3 Intel 4020y (including) 4020y (including)
Core_i3 Intel 4025u (including) 4025u (including)
Core_i3 Intel 4030u (including) 4030u (including)
Core_i3 Intel 4030y (including) 4030y (including)
Core_i3 Intel 4100e (including) 4100e (including)
Core_i3 Intel 4100m (including) 4100m (including)
Core_i3 Intel 4100u (including) 4100u (including)
Core_i3 Intel 4102e (including) 4102e (including)
Core_i3 Intel 4110e (including) 4110e (including)
Core_i3 Intel 4110m (including) 4110m (including)
Core_i3 Intel 4112e (including) 4112e (including)
Core_i3 Intel 4120u (including) 4120u (including)
Core_i3 Intel 4130 (including) 4130 (including)
Core_i3 Intel 4130t (including) 4130t (including)
Core_i3 Intel 4150 (including) 4150 (including)
Core_i3 Intel 4150t (including) 4150t (including)
Core_i3 Intel 4158u (including) 4158u (including)
Core_i3 Intel 4160 (including) 4160 (including)
Core_i3 Intel 4160t (including) 4160t (including)
Core_i3 Intel 4170 (including) 4170 (including)
Core_i3 Intel 4170t (including) 4170t (including)
Core_i3 Intel 4330 (including) 4330 (including)
Core_i3 Intel 4330t (including) 4330t (including)
Core_i3 Intel 4330te (including) 4330te (including)
Core_i3 Intel 4340 (including) 4340 (including)
Core_i3 Intel 4340te (including) 4340te (including)
Core_i3 Intel 4350 (including) 4350 (including)
Core_i3 Intel 4350t (including) 4350t (including)
Core_i3 Intel 4360 (including) 4360 (including)
Core_i3 Intel 4360t (including) 4360t (including)
Core_i3 Intel 4370 (including) 4370 (including)
Core_i3 Intel 4370t (including) 4370t (including)
Core_i3 Intel 5005u (including) 5005u (including)
Core_i3 Intel 5010u (including) 5010u (including)
Core_i3 Intel 5015u (including) 5015u (including)
Core_i3 Intel 5020u (including) 5020u (including)
Core_i3 Intel 5157u (including) 5157u (including)
Core_i3 Intel 6006u (including) 6006u (including)
Core_i3 Intel 6098p (including) 6098p (including)
Core_i3 Intel 6100 (including) 6100 (including)
Core_i3 Intel 6100e (including) 6100e (including)
Core_i3 Intel 6100h (including) 6100h (including)
Core_i3 Intel 6100t (including) 6100t (including)
Core_i3 Intel 6100te (including) 6100te (including)
Core_i3 Intel 6100u (including) 6100u (including)
Core_i3 Intel 6102e (including) 6102e (including)
Core_i3 Intel 6157u (including) 6157u (including)
Core_i3 Intel 6167u (including) 6167u (including)
Core_i3 Intel 6300 (including) 6300 (including)
Core_i3 Intel 6300t (including) 6300t (including)
Core_i3 Intel 6320 (including) 6320 (including)
Core_i3 Intel 8100 (including) 8100 (including)
Core_i3 Intel 8350k (including) 8350k (including)

Extended Description

There are many different kinds of mistakes that introduce information exposures. The severity of the error can range widely, depending on the context in which the product operates, the type of sensitive information that is revealed, and the benefits it may provide to an attacker. Some kinds of sensitive information include:

Information might be sensitive to different parties, each of which may have their own expectations for whether the information should be protected. These parties include:

Information exposures can occur in different ways:

It is common practice to describe any loss of confidentiality as an “information exposure,” but this can lead to overuse of CWE-200 in CWE mapping. From the CWE perspective, loss of confidentiality is a technical impact that can arise from dozens of different weaknesses, such as insecure file permissions or out-of-bounds read. CWE-200 and its lower-level descendants are intended to cover the mistakes that occur in behaviors that explicitly manage, store, transfer, or cleanse sensitive information.

Potential Mitigations

  • Compartmentalize the system to have “safe” areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area.
  • Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

References