Your submission was sent successfully! Close

CVE-2017-5754

Published: 03 January 2018

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

From the Ubuntu security team

Jann Horn discovered that microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Meltdown. A local attacker could use this to expose sensitive information, including kernel memory.

Priority

Critical

CVSS 3 base score: 5.6

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream
Released (57.0.4)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (59.0.1+build1-0ubuntu1)
linux
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.13.0-25.29)
Patches:
Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed by fc2fbc8512ed08d1de7720936fd7d2e4ce02c3a2|local-2017-5754-intel
linux-armadaxp
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

This package is not directly supported by the Ubuntu Security Team
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1001.1)
linux-azure
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1002.2)
linux-azure-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.18.0-1004.4~18.04.1)
linux-euclid
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-flo
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-gcp
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1001.1)
linux-gke
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-goldfish
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-grouper
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.18.0-11.12~18.04.1)
linux-kvm
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1002.2)
linux-linaro-omap
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-linaro-shared
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-linaro-vexpress
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-quantal
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

This package is not directly supported by the Ubuntu Security Team
linux-lts-raring
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-saucy
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

This package is not directly supported by the Ubuntu Security Team
linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-utopic
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-vivid
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-wily
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-maguro
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-mako
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-manta
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-oem
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1002.3)
linux-qcm-msm
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1006.7)
linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

linux-ti-omap4
Launchpad, Ubuntu, Debian
Upstream
Released (4.15~rc6)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Notes

AuthorNote
tyhicks
Variant 3, aka Meltdown
This flaw only affects Intel processors. AMD reports that their
processors are not affected.
The break-fix lines for this CVE are not complete since a large
number of patches are required to mitigate this issue. The commit(s) listed
are chosen as placeholders for automated CVE triage purposes.
ppc64el and s390x kernels were fixed with the following commits:
aa8a5e0062ac940f7659394f4817c948dc8c0667
local-2017-5754-ppc64el
d768bd892fc8f066cd3aa000eb1867bcf32db0ee
local-2017-5754-s390x Unfortunately, the automated CVE triage tooling gets confused since the commits identified by the local-* placeholders were reverted in favor of the upstream commits so they're not included in the break-fix section below.

References