From:
Date: May 15, 2019 2:43AM
On May 14, fixes for CVE-2018-12126, CVE-2018-12127, CVE-2018-12130,
and CVE-2019-11091 were released into the Ubuntu Xenial and Bionic
kernels. These CVEs are security vulnerabilities caused by flaws in the
design of speculative execution hardware in the computer's CPU.
Researchers discovered that memory contents previously stored in
microarchitectural buffers of an Intel CPU core may be visible to other
processes running on the same core.
Details on the vulnerability and our response can be found here:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/MDS
Due to the high complexity of the fixes and the need for a corresponding
CPU microcode update for a complete fix, we are unable to livepatch these
CVEs. Please plan to reboot into an updated kernel as soon as possible.
References:
CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091
沒有留言:
張貼留言