Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2018-3620
Multiple researchers have discovered a vulnerability in the way
the Intel processor designs have implemented speculative execution
of instructions in combination with handling of page-faults. This
flaw could allow an attacker controlling an unprivileged process
to read memory from arbitrary (non-user controlled) addresses,
including from the kernel and all other processes running on the
system or cross guest/host boundaries to read host memory.
This issue covers only attackers running normal processes.
A related issue (CVE-2018-3646) exists with KVM guests,
and is not yet fixed.
CVE-2018-3639
Multiple researchers have discovered that Speculative Store Bypass
(SSB), a feature implemented in many processors, could be used to
read sensitive information from another context. In particular,
code in a software sandbox may be able to read sensitive
information from outside the sandbox. This issue is also known as
Get the latest Linux and open source security news straight to your inbox.