CERT mailing list archives

Intel Side-Channel Vulnerability


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Tue, 14 Aug 2018 13:20:16 -0500

U.S. Department of Homeland Security US-CERT

National Cyber Awareness System:



Intel Side-Channel L1TF Vulnerability [ 
https://www.us-cert.gov/ncas/current-activity/2018/08/14/Intel-Side-Channel-Vulnerability ] 08/14/2018 01:54 PM EDT 
Original release date: August 14, 2018

Intel has released recommendations to address a side-channel vulnerability called L1 Terminal Fault (L1TF) that affects 
multiple Intel microprocessors. An attacker could exploit this vulnerability to obtain sensitive information.



NCCIC encourages users and administrators to review Intel's Security Advisory INTEL-SA-00161 [ 
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.html ], apply the necessary 
mitigations, and refer to software vendors for appropriate patches, when available. 



Additional resources include: 


  * Intel Security First [ 
https://www.intel.com/content/www/us/en/architecture-and-technology/facts-about-side-channel-analysis-and-intel-products.html
 ] 
  * Intel Resources and Response to Side Channel L1 Terminal Fault [ 
https://www.intel.com/content/www/us/en/architecture-and-technology/l1tf.html ] 
  * NCCIC TA18-141A [ https://www.us-cert.gov/ncas/alerts/TA18-141A ]: Side-Channel Vulnerability Variants 3a and 4 
  * NCCIC TA18-004A [ https://www.us-cert.gov/ncas/alerts/TA18-004A ]: Meltdown and Spectre Side-Channel Vulnerability 
Guidance 









________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: normal; font-style: normal; color: 
#333333; } ________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: