Vulnerability Bulletins

DSA-4279 linux - security update

   
Affected software Debian
 
Multiple researchers have discovered a vulnerability in the way theIntel processor designs have implemented speculative execution ofinstructions in combination with handling of page-faults. This flawcould allow an attacker controlling an unprivileged process to readmemory from arbitrary (non-user controlled) addresses, including fromthe kernel and all other processes running on the system or crossguest/host boundaries to read host memory.

More info:

https://www.debian.org/security/2018/dsa-4279