CVE-2018-3646
5.6
MEDIUM
CVSS 3.1
EPSS 2.5%
Description
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
How to fix CVE-2018-3646
To remediate CVE-2018-3646, upgrade the affected package to a fixed version below.
- Alpine/xen—upgrade to 4.11.1-r0 or later
- —upgrade to 3.20180703.1 or later
- —upgrade to 4.17.15-1 or later
- —upgrade to 4.11.1~pre.20180911.5acdd26fdc+dfsg-2 or later
Is CVE-2018-3646 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 4.11.1-r0
- from 0, < 3.20180703.1
- from 0, < 4.17.15-1
- from 0, < 4.11.1~pre.20180911.5acdd26fdc+dfsg-2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.6 | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |