Modern operating systems implement virtualization of physical memory to efficiently use available system resources and provide inter-domain protection through access control and isolation. The L1TF issue was found in the way the x86 microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimisation) in combination with handling of page-faults caused by terminated virtual to physical address resolving process. As a result, an unprivileged attacker could use this flaw to read privileged memory of the kernel or other processes and/or cross guest/host boundaries to read host memory by conducting targeted cache side-channel attacks. CVE-2018-3620: for attack vector against the operating system (Kernel) CVE-2018-3646: for attack vector against virtualization hypervisor (KVM) Upstream patches: ----------------- -> https://git.kernel.org/linus/958f338e96f874a0d29442396d6adf9c1e17aa2d
Statement: This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 may address this issue.
Acknowledgments: Name: Intel OSSIRT (Intel.com)
External References: https://access.redhat.com/security/vulnerabilities/L1TF https://www.redhat.com/en/blog/understanding-l1-terminal-fault-aka-foreshadow-what-you-need-know https://www.redhat.com/en/blog/deeper-look-l1-terminal-fault-aka-foreshadow https://foreshadowattack.eu/ https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-fault https://access.redhat.com/articles/3562741
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1615998]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2018:2390 https://access.redhat.com/errata/RHSA-2018:2390
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:2384 https://access.redhat.com/errata/RHSA-2018:2384
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.3 Extended Update Support Via RHSA-2018:2388 https://access.redhat.com/errata/RHSA-2018:2388
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.4 Extended Update Support Via RHSA-2018:2387 https://access.redhat.com/errata/RHSA-2018:2387
This issue has been addressed in the following products: Red Hat Enterprise Linux 6.6 Advanced Update Support Red Hat Enterprise Linux 6.6 Telco Extended Update Support Via RHSA-2018:2392 https://access.redhat.com/errata/RHSA-2018:2392
This issue has been addressed in the following products: Red Hat Enterprise MRG 2 Via RHSA-2018:2396 https://access.redhat.com/errata/RHSA-2018:2396
This issue has been addressed in the following products: Red Hat Enterprise Linux 6.4 Advanced Update Support Via RHSA-2018:2394 https://access.redhat.com/errata/RHSA-2018:2394
This issue has been addressed in the following products: Red Hat Enterprise Linux 6.5 Advanced Update Support Via RHSA-2018:2393 https://access.redhat.com/errata/RHSA-2018:2393
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.2 Advanced Update Support Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions Red Hat Enterprise Linux 7.2 Telco Extended Update Support Via RHSA-2018:2389 https://access.redhat.com/errata/RHSA-2018:2389
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:2395 https://access.redhat.com/errata/RHSA-2018:2395
This issue has been addressed in the following products: Red Hat Enterprise Linux 6.7 Extended Update Support Via RHSA-2018:2391 https://access.redhat.com/errata/RHSA-2018:2391
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Via RHSA-2018:2403 https://access.redhat.com/errata/RHSA-2018:2403
This issue has been addressed in the following products: RHEV 3.X Hypervisor and Agents for RHEL-6 RHEV 3.X Hypervisor and Agents for RHEL-7 ELS Via RHSA-2018:2404 https://access.redhat.com/errata/RHSA-2018:2404
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Via RHSA-2018:2402 https://access.redhat.com/errata/RHSA-2018:2402
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Extended Lifecycle Support Via RHSA-2018:2602 https://access.redhat.com/errata/RHSA-2018:2602
This issue has been addressed in the following products: Red Hat Enterprise Linux 5.9 Long Life Via RHSA-2018:2603 https://access.redhat.com/errata/RHSA-2018:2603