CVE-2018-3665: Canonical Ubuntu Linux
Medium severity, CVSS 5.6. EPSS: 0.6% chance of exploitation in the next 30 days.
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
- Citrix Xenserver: version 7.0 only; version 7.1 only; version 7.3 only; version 7.4 only; version 7.5 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Freebsd Freebsd: version 11.0 only; version 11.1 only; version 11.2 only
- Intel Core i3: version 330e only; version 330m only; version 330um only; version 350m only; version 370m only; version 380m only; …
- Intel Core i5: version 430m only; version 430um only; version 450m only; version 460m only; version 470um only; version 480m only; …
- Intel Core i7: version 7y75 only; version 610e only; version 620le only; version 620lm only; version 620m only; version 620ue only; …
- Intel Core M: version 5y10 only; version 5y10a only; version 5y10c only; version 5y31 only; version 5y51 only; version 5y70 only; …
- Intel Core m3: version 6y30 only; version 7y30 only; version 7y32 only
- Intel Core m5: version 6y54 only; version 6y57 only
- Intel Core m7: version 6y75 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
Published 2018-06-21. Last modified 2026-06-17.