USN-3756-1: Intel Microcode vulnerabilities
Severity
High
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 14.04
- Canonical Ubuntu 16.04
Description
It was discovered that memory present in the L1 data cache of an Intel CPU core may be exposed to a malicious process that is executing on the CPU core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local attacker in a guest virtual machine could use this to expose sensitive information (memory from other guests or the host OS). (CVE-2018-3646)
Jann Horn and Ken Johnson discovered that microprocessors utilizing speculative execution of a memory read may allow unauthorized memory reads via a sidechannel attack. This flaw is known as Spectre Variant 4. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2018-3639)
Zdenek Sojka, Rudolf Marek, Alex Zuepke, and Innokentiy Sennovskiy discovered that microprocessors that perform speculative reads of system registers may allow unauthorized disclosure of system parameters via a sidechannel attack. This vulnerability is also known as Rogue System Register Read (RSRE). An attacker could use this to expose sensitive information. (CVE-2018-3640)
Affected Cloud Foundry Products and Versions
Severity is high unless otherwise noted.
- Cloud Foundry BOSH trusty-stemcells are vulnerable, including:
- 3363.x versions prior to 3363.74
- 3421.x versions prior to 3421.81
- 3445.x versions prior to 3445.66
- 3468.x versions prior to 3468.67
- 3541.x versions prior to 3541.46
- 3586.x versions prior to 3586.40
- All other stemcells not listed.
- Cloud Foundry BOSH xenial-stemcells are vulnerable, including:
- 97.x versions prior to 97.15
- All other stemcells not listed.
Mitigation
OSS users are strongly encouraged to follow one of the mitigations below:
- The Cloud Foundry project recommends upgrading the following BOSH trusty-stemcells:
- Upgrade 3363.x versions to 3363.74
- Upgrade 3421.x versions to 3421.81
- Upgrade 3445.x versions to 3445.66
- Upgrade 3468.x versions to 3468.67
- Upgrade 3541.x versions to 3541.46
- Upgrade 3586.x versions to 3586.40
- All other stemcells should be upgraded to the latest version available on bosh.io.
- The Cloud Foundry project recommends upgrading the following BOSH xenial-stemcells:
- Upgrade 97.x versions to 97.15
- All other stemcells should be upgraded to the latest version available on bosh.io.