CVE-2018-10846: Medium severity GNU GnuTLS vulnerability
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
Other sources
A cache-based side channel in GnuTLS implementation that leads to plaintext recovery in cross-VM attack setting was found. The attack exploits a novel "Just in Time" PRIME + PROBE attack in combination with a new variant of the original Lucky 13 attack.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10846?
CVE-2018-10846 is a cache-based side channel vulnerability in the GnuTLS implementation that allows an attacker to recover plain text in a cross-VM attack setting.
How severe is CVE-2018-10846?
The severity of CVE-2018-10846 is medium, with a CVSS score of 5.6.
Which software versions are affected by CVE-2018-10846?
The affected software includes GnuTLS version up to and excluding 3.5.18-1ubuntu1.1, 3.5.19 and 3.6.3 (Ubuntu), 3.4.10-4ubuntu1.5 (Xenial), 3.6.7-4+deb10u8, 3.6.7-4+deb10u10, 3.7.1-5+deb11u3, 3.7.9-2, 3.8.1-4 (Debian), as well as other specific versions and distributions.
How can I fix CVE-2018-10846?
To fix CVE-2018-10846, you should update GnuTLS to version 3.5.18-1ubuntu1.1 (Ubuntu), 3.5.19 or 3.6.3 (Ubuntu), 3.4.10-4ubuntu1.5 (Xenial), or other specific fixed versions for different distributions.
Where can I find more information about CVE-2018-10846?
You can find more information about CVE-2018-10846 on the SecurityFocus and Red Hat websites.