Bug 1890356 (CVE-2020-8698)

Summary: CVE-2020-8698 hw: Fast forward store predictor
Product: [Other] Security Response Reporter: Wade Mealing <wmealing>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: esyr, pmatouse, poros, security-response-team, skozina
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the CPU microarchitecture where a local attacker is able to abuse a timing issue which may allow them to infer internal architectural state from previous executions on the CPU.
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-11-11 14:21:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1893214, 1893215, 1893216, 1893217, 1893224, 1893225, 1893226, 1893227, 1893228, 1893229, 1893230, 1893231, 1893232, 1893233, 1893234, 1893235, 1893236, 1893237, 1893238    
Bug Blocks: 1890353    

Description Wade Mealing 2020-10-22 00:42:55 UTC
A flaw was found in the CPU microarchitecture where a local attacker is able to abuse a timing issue which may allow them to infer internal architectural state from previous executions on the CPU.

Comment 3 Petr Matousek 2020-11-10 19:37:44 UTC
External References:

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381.html

Comment 4 Petr Matousek 2020-11-10 19:39:52 UTC
Acknowledgments:

Name: Intel

Comment 8 errata-xmlrpc 2020-11-11 09:46:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:5085 https://access.redhat.com/errata/RHSA-2020:5085

Comment 9 errata-xmlrpc 2020-11-11 10:00:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2020:5084 https://access.redhat.com/errata/RHSA-2020:5084

Comment 10 errata-xmlrpc 2020-11-11 10:13:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:5083 https://access.redhat.com/errata/RHSA-2020:5083

Comment 11 Product Security DevOps Team 2020-11-11 14:21:25 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-8698

Comment 23 errata-xmlrpc 2020-11-23 17:37:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6.6 Advanced Update Support

Via RHSA-2020:5184 https://access.redhat.com/errata/RHSA-2020:5184

Comment 24 errata-xmlrpc 2020-11-23 17:44:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.3 Advanced Update Support
  Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.3 Telco Extended Update Support

Via RHSA-2020:5183 https://access.redhat.com/errata/RHSA-2020:5183

Comment 25 errata-xmlrpc 2020-11-23 17:45:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.4 Advanced Update Support
  Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.4 Telco Extended Update Support

Via RHSA-2020:5182 https://access.redhat.com/errata/RHSA-2020:5182

Comment 26 errata-xmlrpc 2020-11-23 17:47:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions

Via RHSA-2020:5186 https://access.redhat.com/errata/RHSA-2020:5186

Comment 27 errata-xmlrpc 2020-11-23 17:55:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.6 Extended Update Support

Via RHSA-2020:5181 https://access.redhat.com/errata/RHSA-2020:5181

Comment 28 errata-xmlrpc 2020-11-23 17:57:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2020:5185 https://access.redhat.com/errata/RHSA-2020:5185

Comment 29 errata-xmlrpc 2020-11-23 18:55:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6.5 Advanced Update Support

Via RHSA-2020:5189 https://access.redhat.com/errata/RHSA-2020:5189

Comment 30 errata-xmlrpc 2020-11-23 18:56:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.2 Advanced Update Support

Via RHSA-2020:5188 https://access.redhat.com/errata/RHSA-2020:5188

Comment 31 errata-xmlrpc 2020-11-23 19:21:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Extended Update Support

Via RHSA-2020:5190 https://access.redhat.com/errata/RHSA-2020:5190

Comment 39 errata-xmlrpc 2020-12-08 10:34:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2020:5369 https://access.redhat.com/errata/RHSA-2020:5369

Comment 40 errata-xmlrpc 2021-08-09 09:51:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:3027 https://access.redhat.com/errata/RHSA-2021:3027

Comment 41 errata-xmlrpc 2021-08-09 10:09:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2021:3028 https://access.redhat.com/errata/RHSA-2021:3028

Comment 43 errata-xmlrpc 2021-08-10 13:40:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Extended Update Support

Via RHSA-2021:3029 https://access.redhat.com/errata/RHSA-2021:3029

Comment 44 errata-xmlrpc 2021-08-17 08:30:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:3176 https://access.redhat.com/errata/RHSA-2021:3176

Comment 45 errata-xmlrpc 2021-08-24 09:54:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.4 Advanced Update Support
  Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.4 Telco Extended Update Support

Via RHSA-2021:3255 https://access.redhat.com/errata/RHSA-2021:3255

Comment 46 errata-xmlrpc 2021-08-31 07:56:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.2 Advanced Update Support

Via RHSA-2021:3323 https://access.redhat.com/errata/RHSA-2021:3323

Comment 47 errata-xmlrpc 2021-08-31 08:04:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.3 Advanced Update Support

Via RHSA-2021:3322 https://access.redhat.com/errata/RHSA-2021:3322

Comment 48 errata-xmlrpc 2021-08-31 08:24:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.6 Advanced Update Support
  Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.6 Telco Extended Update Support

Via RHSA-2021:3317 https://access.redhat.com/errata/RHSA-2021:3317

Comment 49 errata-xmlrpc 2021-08-31 09:21:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:3364 https://access.redhat.com/errata/RHSA-2021:3364