CVE-2017-5715: Infoleak
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited.
Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks.
Other sources
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.18-348.39.1.el5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.18-430.el5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-696.28.1.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-220.76.2.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-358.84.2.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-431.85.2.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-504.64.4.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-573.55.2.el6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.11.1.rt56.639.el7 - Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 0:033-502.el7_4.1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-862.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-49.8.1.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-327.66.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.48.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.25.2.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 1:3.10.0-693.11.1.rt56.606.el6 - Upgrade
Upgrade
debian/amd64-microcodeto a version that resolves this vulnerability.Fixed in 3.20240820.1~deb11u1Fixed in 3.20250311.1~deb11u1Fixed in 3.20250311.1~deb12u1Fixed in 3.20230719.1~deb12u1Fixed in 3.20250311.1Fixed in 3.20251202.1 - Upgrade
Upgrade
debian/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240813.1~deb11u1Fixed in 3.20250812.1~deb11u1Fixed in 3.20251111.1~deb12u1Fixed in 3.20250812.1~deb12u1Fixed in 3.20251111.1~deb13u1Fixed in 3.20250812.1~deb13u1Fixed in 3.20260227.1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.100-1Fixed in 7.1.3-1Fixed in 7.1.6-1 - Upgrade
Upgrade
debian/nvidia-graphics-driversto a version that resolves this vulnerability.Fixed in 470.256.02-2Fixed in 535.261.03-1Fixed in 550.163.01-2Fixed in 550.163.01-5.1 - Upgrade
Upgrade
debian/nvidia-graphics-drivers-legacy-340xxto a version that resolves this vulnerability.Fixed in 340.108-27 - Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u5Fixed in 1:7.2+dfsg-7+deb12u18Fixed in 1:7.2+dfsg-7+deb12u15Fixed in 1:10.0.11+ds-0+deb13u1Fixed in 1:10.0.2+ds-2+deb13u1Fixed in 1:11.0.3+ds-2 - Upgrade
Upgrade
debian/virtualboxto a version that resolves this vulnerability.Fixed in 7.2.14-dfsg-1 - Upgrade
Upgrade
debian/xento a version that resolves this vulnerability.Fixed in 4.14.6-1Fixed in 4.14.5+94-ge49571868d-1Fixed in 4.17.5+72-g01140da4e8-1Fixed in 4.20.2+37-g61ff35323e-0+deb13u1Fixed in 4.20.2+7-g1badcf5035-0+deb13u1Fixed in 4.20.3+127-gc42374a105-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2017-5715?
The severity of CVE-2017-5715 is high due to the potential for unauthorized access to sensitive information through speculative execution attacks.
How do I fix CVE-2017-5715?
To fix CVE-2017-5715, ensure that your system firmware and operating system are updated with the latest patches provided by vendors.
What types of systems are affected by CVE-2017-5715?
CVE-2017-5715 affects a wide range of modern processors from various manufacturers that implement speculative execution.
Can CVE-2017-5715 be exploited remotely?
Yes, CVE-2017-5715 can potentially be exploited remotely by attackers to access sensitive data without local access to the system.
What should I do if my organization is affected by CVE-2017-5715?
If your organization is affected by CVE-2017-5715, it is recommended to apply updates, monitor for unusual activity, and review security policies regarding system access.