CVE-2018-5407: Canonical Ubuntu Linux
Medium severity, CVSS 4.7. EPSS: 3.4% chance of exploitation in the next 30 days.
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Node.js Node.js: before 6.14.4 (fixed in 6.14.4); from 8.0.0, before 8.11.4 (fixed in 8.11.4); from 10.0.0, before 10.9.0 (fixed in 10.9.0)
- OpenSSL OpenSSL: from 1.0.2, before 1.0.2q (fixed in 1.0.2q); from 1.1.0, before 1.1.0i (fixed in 1.1.0i)
- Oracle API Gateway: version 11.1.2.4.0 only
- Oracle Application Server: version 0.9.8 only; version 1.0.0 only; version 1.0.1 only
- Oracle Enterprise Manager Base Platform: version 12.1.0.5.0 only; version 13.2.0.0.0 only; version 13.3.0.0.0 only
- Oracle Enterprise Manager Ops Center: version 12.3.3 only
- Oracle MySQL Enterprise Backup: up to and including 3.12.3; from 3.12.4, up to and including 4.1.2
- Oracle PeopleSoft Enterprise PeopleTools: version 8.55 only; version 8.56 only; version 8.57 only
- Oracle Primavera p6 Enterprise Project Portfolio Management: from 17.7, up to and including 17.12; version 8.4 only; version 15.1 only; version 15.2 only; version 16.1 only; version 16.2 only; …
- Oracle Tuxedo: version 12.1.1.0.0 only
- Oracle Vm VirtualBox: before 6.0.0 (fixed in 6.0.0)
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only; version 7.6 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Tenable Nessus: before 8.1.1 (fixed in 8.1.1)
Published 2018-11-15. Last modified 2026-10-08.