Ask the Community
Groups
CVE-2018-3665 Kernel: FPU state information leakage via lazy FPU restore - Connect IT Community | Kaseya
<main> <article class="userContent"> <h3 data-id="cve-id"><strong>CVE ID</strong></h3> <p>CVE-2018-3665</p> <h3 data-id="description"><strong>DESCRIPTION</strong></h3> <p>A Floating Point Unit (FPU) state information leakage flaw was found in the way the Linux kernel saved and restored the FPU state during task switch. Linux kernels that follow the "Lazy FPU Restore" scheme are vulnerable to the FPU state information leakage issue. An unprivileged local attacker could use this flaw to read FPU state bits by conducting targeted cache side-channel attacks, similar to the Meltdown vulnerability disclosed earlier this year.<br><br>CVSS3 Base Score 5.6 Medium<br><br><br><br><br><br> </p> <h3 data-id="resolution"><strong>RESOLUTION</strong></h3> <p>Resolution:<br>Apply Unitrends security update v10.29 from 07/27/2018 or later,<br> containing kernel-2.6.32-754.2.1.el6</p> <h3 data-id="link-to-advisories"><strong>LINK TO ADVISORIES</strong></h3> <p></p> <ul><li><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2Fcve-2018-3665%250D%250Ahttps%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2018-3665%250D%250Ahttps%3A%2F%2Faccess.redhat.com%2Ferrata%2FRHSA-2018%3A2164">https://access.redhat.com/security/cve/cve-2018-3665 https://nvd.nist.gov/vuln/detail/CVE-2018-3665 https://access.redhat.com/errata/RHSA-2018:2164</a></li></ul> </article> </main>