CVE-2018-3639
67Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 5.5epss 61%
from disclosure to weapon0 days
Published on NVDMay 22
1st PoCMay 22
VulnCheck+644d
exploitation probability
61%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
In short
A flaw in how processors handle memory operations allows local attackers to read sensitive information that should be hidden. The processor sometimes reads data before confirming all previous write operations are complete, creating a side-channel that leaks information.
Technical detail
CVE-2018-3639 (Speculative Store Bypass) exploits speculative execution in processors that load memory before resolving prior store addresses. Local attackers can infer sensitive data through timing analysis and cache-state observation; requires local user access and leverages the processor's speculation mechanism to bypass memory ordering protections.
Summary generated and translated by AI from the official description.
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Intel Corporation · Multiplepublic PoCs found — 9✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44695githubgithub.com/mmxsrup/CVE-2018-3639★ 15githubgithub.com/tyhicks/ssbd-tools★ 9githubgithub.com/Shuiliusheng/CVE-2018-3639-specter-v4-★ 1githubgithub.com/malindarathnayake/Intel-CVE-2018-3639-Mitigation_RegistryUpdate★ 0vulncheckvulncheck.com/xdb/013f6a378013unverifiedvulncheckvulncheck.com/xdb/93719e9e1986unverifiedvulncheckvulncheck.com/xdb/a7fd64963d55unverifiedcve_referencewww.exploit-db.com/exploits/44695/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.htmlhttps://access.redhat.com/errata/RHSA-2018:1629https://access.redhat.com/errata/RHSA-2018:1630https://access.redhat.com/errata/RHSA-2018:1632https://access.redhat.com/errata/RHSA-2018:1633https://access.redhat.com/errata/RHSA-2018:1635https://access.redhat.com/errata/RHSA-2018:1636https://access.redhat.com/errata/RHSA-2018:1637https://access.redhat.com/errata/RHSA-2018:1638https://access.redhat.com/errata/RHSA-2018:1639