USN-3756-1: Intel Microcode vulnerabilities
Severity
High
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 14.04
 - Canonical Ubuntu 16.04
 
Description
It was discovered that memory present in the L1 data cache of an Intel CPU core may be exposed to a malicious process that is executing on the CPU core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local attacker in a guest virtual machine could use this to expose sensitive information (memory from other guests or the host OS). (CVE-2018-3646)
Jann Horn and Ken Johnson discovered that microprocessors utilizing speculative execution of a memory read may allow unauthorized memory reads via a sidechannel attack. This flaw is known as Spectre Variant 4. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2018-3639)
Zdenek Sojka, Rudolf Marek, Alex Zuepke, and Innokentiy Sennovskiy discovered that microprocessors that perform speculative reads of system registers may allow unauthorized disclosure of system parameters via a sidechannel attack. This vulnerability is also known as Rogue System Register Read (RSRE). An attacker could use this to expose sensitive information. (CVE-2018-3640)
Affected Cloud Foundry Products and Versions
Severity is high unless otherwise noted.
- Cloud Foundry BOSH trusty-stemcells are vulnerable, including:
- 3363.x versions prior to 3363.74
 - 3421.x versions prior to 3421.81
 - 3445.x versions prior to 3445.66
 - 3468.x versions prior to 3468.67
 - 3541.x versions prior to 3541.46
 - 3586.x versions prior to 3586.40
 - All other stemcells not listed.
 
 - Cloud Foundry BOSH xenial-stemcells are vulnerable, including:
- 97.x versions prior to 97.15
 - All other stemcells not listed.
 
 
Mitigation
OSS users are strongly encouraged to follow one of the mitigations below:
- The Cloud Foundry project recommends upgrading the following BOSH trusty-stemcells:
- Upgrade 3363.x versions to 3363.74
 - Upgrade 3421.x versions to 3421.81
 - Upgrade 3445.x versions to 3445.66
 - Upgrade 3468.x versions to 3468.67
 - Upgrade 3541.x versions to 3541.46
 - Upgrade 3586.x versions to 3586.40
 - All other stemcells should be upgraded to the latest version available on bosh.io.
 
 - The Cloud Foundry project recommends upgrading the following BOSH xenial-stemcells:
- Upgrade 97.x versions to 97.15
 - All other stemcells should be upgraded to the latest version available on bosh.io.
 
 
    