vulnerability

FreeBSD: VID-74daa370-2797-11e8-95ec-a4badb2f4699 (CVE-2017-5754): FreeBSD -- Speculative Execution Vulnerabilities

Severity
5
CVSS
(AV:L/AC:M/Au:N/C:C/I:N/A:N)
Published
Mar 14, 2018
Added
Mar 15, 2018
Modified
Dec 10, 2025

Description

Problem Description: A number of issues relating to speculative execution were found last year and publicly announced January 3rd. Two of these, known as Meltdown and Spectre V2, are addressed here. CVE-2017-5754 (Meltdown) - ------------------------ This issue relies on an affected CPU speculatively executing instructions beyond a faulting instruction. When this happens, changes to architectural state are not committed, but observable changes may be left in micro- architectural state (for example, cache). This may be used to infer privileged data. CVE-2017-5715 (Spectre V2) - -------------------------- Spectre V2 uses branch target injection to speculatively execute kernel code at an address under the control of an attacker. Impact: An attacker may be able to read secret data from the kernel or from a process when executing untrusted code (for example, in a web browser).

Solution

freebsd-upgrade-base-11_1-release-p8
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.