USN-3652-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-3652-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3652-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3652-1
Related
Published
2018-05-22T03:30:03.441009Z
Modified
2018-05-22T03:30:03.441009Z
Summary
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem vulnerability
Details

Jann Horn and Ken Johnson discovered that microprocessors utilizing speculative execution of a memory read may allow unauthorized memory reads via a sidechannel attack. This flaw is known as Spectre Variant 4. A local attacker could use this to expose sensitive information, including kernel memory.

References

Affected packages

Ubuntu:18.04:LTS / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux@4.15.0-22.24?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-22.24

Affected versions

4.*

4.13.0-16.19
4.13.0-17.20
4.13.0-25.29
4.13.0-32.35
4.15.0-10.11
4.15.0-12.13
4.15.0-13.14
4.15.0-15.16
4.15.0-19.20
4.15.0-20.21

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "fs-secondary-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "ppp-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "parport-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-image-4.15.0-22-generic-dbgsym": "4.15.0-22.24",
            "pata-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "dasd-extra-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "nic-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-tools-4.15.0-22-lowlatency": "4.15.0-22.24",
            "vlan-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "crypto-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "fs-core-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "fs-core-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-image-4.15.0-22-snapdragon-dbgsym": "4.15.0-22.24",
            "linux-headers-4.15.0-22-generic-lpae": "4.15.0-22.24",
            "linux-headers-4.15.0-22-snapdragon": "4.15.0-22.24",
            "nfs-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-modules-4.15.0-22-generic-lpae": "4.15.0-22.24",
            "scsi-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "fs-secondary-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "block-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "ppp-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "md-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-tools-4.15.0-22": "4.15.0-22.24",
            "linux-image-4.15.0-22-generic": "4.15.0-22.24",
            "linux-cloud-tools-4.15.0-22-dbgsym": "4.15.0-22.24",
            "linux-tools-4.15.0-22-dbgsym": "4.15.0-22.24",
            "pcmcia-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "mouse-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "nic-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "nic-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-image-unsigned-4.15.0-22-generic-dbgsym": "4.15.0-22.24",
            "mouse-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "scsi-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "crypto-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "nfs-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "serial-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "ipmi-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "plip-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "pcmcia-storage-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "block-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "storage-core-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-cloud-tools-common": "4.15.0-22.24",
            "virtio-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-modules-4.15.0-22-generic": "4.15.0-22.24",
            "fat-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-libc-dev": "4.15.0-22.24",
            "linux-tools-4.15.0-22-generic-lpae": "4.15.0-22.24",
            "linux-image-unsigned-4.15.0-22-generic": "4.15.0-22.24",
            "linux-cloud-tools-4.15.0-22-generic": "4.15.0-22.24",
            "plip-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "nic-shared-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "vlan-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-image-4.15.0-22-lowlatency": "4.15.0-22.24",
            "nic-usb-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-cloud-tools-4.15.0-22-lowlatency": "4.15.0-22.24",
            "fat-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "message-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-image-unsigned-4.15.0-22-lowlatency-dbgsym": "4.15.0-22.24",
            "virtio-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "storage-core-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "nic-pcmcia-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "fs-core-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "parport-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-image-4.15.0-22-generic-lpae-dbgsym": "4.15.0-22.24",
            "kernel-image-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-image-unsigned-4.15.0-22-lowlatency": "4.15.0-22.24",
            "fb-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-tools-4.15.0-22-snapdragon": "4.15.0-22.24",
            "nfs-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "crypto-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-tools-common": "4.15.0-22.24",
            "linux-udebs-snapdragon": "4.15.0-22.24",
            "linux-headers-4.15.0-22-lowlatency": "4.15.0-22.24",
            "ipmi-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "scsi-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "md-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-headers-4.15.0-22-generic": "4.15.0-22.24",
            "ppp-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "plip-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "storage-core-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-udebs-generic": "4.15.0-22.24",
            "usb-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "dasd-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "md-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "input-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "kernel-image-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "irda-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-tools-4.15.0-22-generic": "4.15.0-22.24",
            "linux-image-4.15.0-22-lowlatency-dbgsym": "4.15.0-22.24",
            "linux-cloud-tools-4.15.0-22": "4.15.0-22.24",
            "mouse-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "block-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "parport-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "fs-secondary-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-image-4.15.0-22-snapdragon": "4.15.0-22.24",
            "multipath-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "firewire-core-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "irda-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "multipath-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "multipath-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "sata-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-image-4.15.0-22-generic-lpae": "4.15.0-22.24",
            "linux-source-4.15.0": "4.15.0-22.24",
            "usb-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "vlan-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "irda-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "nic-shared-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "fat-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-doc": "4.15.0-22.24",
            "nic-usb-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "ipmi-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-modules-extra-4.15.0-22-generic": "4.15.0-22.24",
            "linux-modules-4.15.0-22-snapdragon": "4.15.0-22.24",
            "message-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "input-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "linux-tools-host": "4.15.0-22.24",
            "linux-modules-4.15.0-22-lowlatency": "4.15.0-22.24",
            "nic-shared-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "nic-usb-modules-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "linux-udebs-generic-lpae": "4.15.0-22.24",
            "sata-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "kernel-image-4.15.0-22-generic-lpae-di": "4.15.0-22.24",
            "input-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "linux-headers-4.15.0-22": "4.15.0-22.24",
            "floppy-modules-4.15.0-22-generic-di": "4.15.0-22.24",
            "usb-modules-4.15.0-22-snapdragon-di": "4.15.0-22.24",
            "sata-modules-4.15.0-22-generic-di": "4.15.0-22.24"
        }
    ]
}

Ubuntu:18.04:LTS / linux-aws

Package

Name
linux-aws
Purl
pkg:deb/ubuntu/linux-aws@4.15.0-1009.9?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1009.9

Affected versions

4.*

4.15.0-1001.1
4.15.0-1003.3
4.15.0-1005.5
4.15.0-1006.6
4.15.0-1007.7

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-aws-headers-4.15.0-1009": "4.15.0-1009.9",
            "linux-aws-tools-4.15.0-1009": "4.15.0-1009.9",
            "linux-headers-4.15.0-1009-aws": "4.15.0-1009.9",
            "linux-image-4.15.0-1009-aws-dbgsym": "4.15.0-1009.9",
            "linux-image-4.15.0-1009-aws": "4.15.0-1009.9",
            "linux-aws-tools-4.15.0-1009-dbgsym": "4.15.0-1009.9",
            "linux-modules-4.15.0-1009-aws": "4.15.0-1009.9",
            "linux-tools-4.15.0-1009-aws": "4.15.0-1009.9"
        }
    ]
}

Ubuntu:18.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@4.15.0-1012.12?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1012.12

Affected versions

4.*

4.15.0-1002.2
4.15.0-1003.3
4.15.0-1004.4
4.15.0-1008.8
4.15.0-1009.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-unsigned-4.15.0-1012-azure-dbgsym": "4.15.0-1012.12",
            "linux-headers-4.15.0-1012-azure": "4.15.0-1012.12",
            "linux-image-unsigned-4.15.0-1012-azure": "4.15.0-1012.12",
            "linux-modules-extra-4.15.0-1012-azure": "4.15.0-1012.12",
            "linux-azure-cloud-tools-4.15.0-1012-dbgsym": "4.15.0-1012.12",
            "linux-tools-4.15.0-1012-azure": "4.15.0-1012.12",
            "linux-cloud-tools-4.15.0-1012-azure": "4.15.0-1012.12",
            "linux-azure-tools-4.15.0-1012-dbgsym": "4.15.0-1012.12",
            "linux-modules-4.15.0-1012-azure": "4.15.0-1012.12",
            "linux-azure-tools-4.15.0-1012": "4.15.0-1012.12",
            "linux-azure-cloud-tools-4.15.0-1012": "4.15.0-1012.12",
            "linux-azure-headers-4.15.0-1012": "4.15.0-1012.12"
        }
    ]
}

Ubuntu:18.04:LTS / linux-gcp

Package

Name
linux-gcp
Purl
pkg:deb/ubuntu/linux-gcp@4.15.0-1008.8?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1008.8

Affected versions

4.*

4.15.0-1001.1
4.15.0-1003.3
4.15.0-1005.5
4.15.0-1006.6

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-gcp-tools-4.15.0-1008-dbgsym": "4.15.0-1008.8",
            "linux-gcp-headers-4.15.0-1008": "4.15.0-1008.8",
            "linux-tools-4.15.0-1008-gcp": "4.15.0-1008.8",
            "linux-modules-extra-4.15.0-1008-gcp": "4.15.0-1008.8",
            "linux-gcp-tools-4.15.0-1008": "4.15.0-1008.8",
            "linux-headers-4.15.0-1008-gcp": "4.15.0-1008.8",
            "linux-image-4.15.0-1008-gcp": "4.15.0-1008.8",
            "linux-modules-4.15.0-1008-gcp": "4.15.0-1008.8",
            "linux-image-4.15.0-1008-gcp-dbgsym": "4.15.0-1008.8"
        }
    ]
}

Ubuntu:18.04:LTS / linux-kvm

Package

Name
linux-kvm
Purl
pkg:deb/ubuntu/linux-kvm@4.15.0-1010.10?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1010.10

Affected versions

4.*

4.15.0-1002.2
4.15.0-1003.3
4.15.0-1004.4
4.15.0-1006.6
4.15.0-1008.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-modules-4.15.0-1010-kvm": "4.15.0-1010.10",
            "linux-tools-4.15.0-1010-kvm": "4.15.0-1010.10",
            "linux-image-4.15.0-1010-kvm-dbgsym": "4.15.0-1010.10",
            "linux-kvm-tools-4.15.0-1010-dbgsym": "4.15.0-1010.10",
            "linux-image-4.15.0-1010-kvm": "4.15.0-1010.10",
            "linux-headers-4.15.0-1010-kvm": "4.15.0-1010.10",
            "linux-kvm-headers-4.15.0-1010": "4.15.0-1010.10",
            "linux-kvm-tools-4.15.0-1010": "4.15.0-1010.10"
        }
    ]
}

Ubuntu:18.04:LTS / linux-oem

Package

Name
linux-oem
Purl
pkg:deb/ubuntu/linux-oem@4.15.0-1006.9?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1006.9

Affected versions

4.*

4.15.0-1002.3
4.15.0-1004.5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "parport-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "multipath-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-image-unsigned-4.15.0-1006-oem-dbgsym": "4.15.0-1006.9",
            "kernel-image-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-oem-headers-4.15.0-1006": "4.15.0-1006.9",
            "vlan-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "nic-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-headers-4.15.0-1006-oem": "4.15.0-1006.9",
            "fb-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "ipmi-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-image-unsigned-4.15.0-1006-oem": "4.15.0-1006.9",
            "scsi-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "fs-core-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "fs-secondary-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "crypto-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-oem-tools-4.15.0-1006-dbgsym": "4.15.0-1006.9",
            "input-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "nfs-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "sata-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "mouse-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "md-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "nic-pcmcia-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "usb-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "pcmcia-storage-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "firewire-core-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "serial-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "plip-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "nic-usb-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "fat-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-tools-4.15.0-1006-oem": "4.15.0-1006.9",
            "irda-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "pata-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "floppy-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-udebs-oem": "4.15.0-1006.9",
            "virtio-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "block-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-modules-4.15.0-1006-oem": "4.15.0-1006.9",
            "message-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "ppp-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "storage-core-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "nic-shared-modules-4.15.0-1006-oem-di": "4.15.0-1006.9",
            "linux-oem-tools-4.15.0-1006": "4.15.0-1006.9",
            "pcmcia-modules-4.15.0-1006-oem-di": "4.15.0-1006.9"
        }
    ]
}