Show plain JSON{"affected_release": [{"advisory": "RHSA-2019:1169", "cpe": "cpe:/o:redhat:enterprise_linux:6", "package": "kernel-0:2.6.32-754.14.2.el6", "product_name": "Red Hat Enterprise Linux 6", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1180", "cpe": "cpe:/o:redhat:enterprise_linux:6", "package": "libvirt-0:0.10.2-64.el6_10.1", "product_name": "Red Hat Enterprise Linux 6", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1181", "cpe": "cpe:/o:redhat:enterprise_linux:6", "package": "qemu-kvm-2:0.12.1.2-2.506.el6_10.3", "product_name": "Red Hat Enterprise Linux 6", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1196", "cpe": "cpe:/o:redhat:rhel_aus:6.5", "package": "kernel-0:2.6.32-431.94.2.el6", "product_name": "Red Hat Enterprise Linux 6.5 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1197", "cpe": "cpe:/o:redhat:rhel_aus:6.5", "package": "libvirt-0:0.10.2-29.el6_5.18", "product_name": "Red Hat Enterprise Linux 6.5 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1198", "cpe": "cpe:/o:redhat:rhel_aus:6.5", "package": "qemu-kvm-2:0.12.1.2-2.415.el6_5.20", "product_name": "Red Hat Enterprise Linux 6.5 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1193", "cpe": "cpe:/o:redhat:rhel_aus:6.6", "package": "kernel-0:2.6.32-504.78.2.el6", "product_name": "Red Hat Enterprise Linux 6.6 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1194", "cpe": "cpe:/o:redhat:rhel_aus:6.6", "package": "libvirt-0:0.10.2-46.el6_6.10", "product_name": "Red Hat Enterprise Linux 6.6 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1195", "cpe": "cpe:/o:redhat:rhel_aus:6.6", "package": "qemu-kvm-2:0.12.1.2-2.448.el6_6.8", "product_name": "Red Hat Enterprise Linux 6.6 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1176", "cpe": "cpe:/a:redhat:rhel_extras_rt:7", "package": "kernel-rt-0:3.10.0-957.12.2.rt56.929.el7", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1168", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "kernel-0:3.10.0-957.12.2.el7", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1177", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "libvirt-0:4.5.0-10.el7_6.9", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1178", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "qemu-kvm-10:1.5.3-160.el7_6.2", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1172", "cpe": "cpe:/o:redhat:rhel_aus:7.2", "package": "kernel-0:3.10.0-327.78.2.el7", "product_name": "Red Hat Enterprise Linux 7.2 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1186", "cpe": "cpe:/o:redhat:rhel_aus:7.2", "package": "libvirt-0:1.2.17-13.el7_2.10", "product_name": "Red Hat Enterprise Linux 7.2 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1188", "cpe": "cpe:/o:redhat:rhel_aus:7.2", "package": "qemu-kvm-10:1.5.3-105.el7_2.19", "product_name": "Red Hat Enterprise Linux 7.2 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1172", "cpe": "cpe:/o:redhat:rhel_tus:7.2", "package": "kernel-0:3.10.0-327.78.2.el7", "product_name": "Red Hat Enterprise Linux 7.2 Telco Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1186", "cpe": "cpe:/o:redhat:rhel_tus:7.2", "package": "libvirt-0:1.2.17-13.el7_2.10", "product_name": "Red Hat Enterprise Linux 7.2 Telco Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1188", "cpe": "cpe:/o:redhat:rhel_tus:7.2", "package": "qemu-kvm-10:1.5.3-105.el7_2.19", "product_name": "Red Hat Enterprise Linux 7.2 Telco Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1172", "cpe": "cpe:/o:redhat:rhel_e4s:7.2", "package": "kernel-0:3.10.0-327.78.2.el7", "product_name": "Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1186", "cpe": "cpe:/o:redhat:rhel_e4s:7.2", "package": "libvirt-0:1.2.17-13.el7_2.10", "product_name": "Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1188", "cpe": "cpe:/o:redhat:rhel_e4s:7.2", "package": "qemu-kvm-10:1.5.3-105.el7_2.19", "product_name": "Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1171", "cpe": "cpe:/o:redhat:rhel_aus:7.3", "package": "kernel-0:3.10.0-514.64.2.el7", "product_name": "Red Hat Enterprise Linux 7.3 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1187", "cpe": "cpe:/o:redhat:rhel_aus:7.3", "package": "libvirt-0:2.0.0-10.el7_3.14", "product_name": "Red Hat Enterprise Linux 7.3 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1189", "cpe": "cpe:/o:redhat:rhel_aus:7.3", "package": "qemu-kvm-10:1.5.3-126.el7_3.17", "product_name": "Red Hat Enterprise Linux 7.3 Advanced Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1171", "cpe": "cpe:/o:redhat:rhel_tus:7.3", "package": "kernel-0:3.10.0-514.64.2.el7", "product_name": "Red Hat Enterprise Linux 7.3 Telco Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1187", "cpe": "cpe:/o:redhat:rhel_tus:7.3", "package": "libvirt-0:2.0.0-10.el7_3.14", "product_name": "Red Hat Enterprise Linux 7.3 Telco Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1189", "cpe": "cpe:/o:redhat:rhel_tus:7.3", "package": "qemu-kvm-10:1.5.3-126.el7_3.17", "product_name": "Red Hat Enterprise Linux 7.3 Telco Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1171", "cpe": "cpe:/o:redhat:rhel_e4s:7.3", "package": "kernel-0:3.10.0-514.64.2.el7", "product_name": "Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1187", "cpe": "cpe:/o:redhat:rhel_e4s:7.3", "package": "libvirt-0:2.0.0-10.el7_3.14", "product_name": "Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1189", "cpe": "cpe:/o:redhat:rhel_e4s:7.3", "package": "qemu-kvm-10:1.5.3-126.el7_3.17", "product_name": "Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1170", "cpe": "cpe:/o:redhat:rhel_eus:7.4", "package": "kernel-0:3.10.0-693.47.2.el7", "product_name": "Red Hat Enterprise Linux 7.4 Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1184", "cpe": "cpe:/o:redhat:rhel_eus:7.4", "package": "libvirt-0:3.2.0-14.el7_4.13", "product_name": "Red Hat Enterprise Linux 7.4 Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1185", "cpe": "cpe:/o:redhat:rhel_eus:7.4", "package": "qemu-kvm-10:1.5.3-141.el7_4.10", "product_name": "Red Hat Enterprise Linux 7.4 Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1155", "cpe": "cpe:/o:redhat:rhel_eus:7.5", "package": "kernel-0:3.10.0-862.32.2.el7", "product_name": "Red Hat Enterprise Linux 7.5 Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1182", "cpe": "cpe:/o:redhat:rhel_eus:7.5", "package": "libvirt-0:3.9.0-14.el7_5.9", "product_name": "Red Hat Enterprise Linux 7.5 Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1183", "cpe": "cpe:/o:redhat:rhel_eus:7.5", "package": "qemu-kvm-10:1.5.3-156.el7_5.7", "product_name": "Red Hat Enterprise Linux 7.5 Extended Update Support", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1175", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "virt:rhel-8000020190510171727.55190bc5", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1174", "cpe": "cpe:/a:redhat:enterprise_linux:8::nfv", "package": "kernel-rt-0:4.18.0-80.1.2.rt9.145.el8_0", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1167", "cpe": "cpe:/o:redhat:enterprise_linux:8", "package": "kernel-0:4.18.0-80.1.2.el8_0", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1455", "cpe": "cpe:/a:redhat:advanced_virtualization:8::el8", "package": "virt:8.0.0-8000020190530233731.55190bc5", "product_name": "Red Hat Enterprise Linux 8 Advanced Virtualization", "release_date": "2019-06-11T00:00:00Z"}, {"advisory": "RHSA-2019:1190", "cpe": "cpe:/a:redhat:enterprise_mrg:2:server:el6", "package": "kernel-rt-1:3.10.0-693.47.2.rt56.641.el6rt", "product_name": "Red Hat Enterprise MRG 2", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1200", "cpe": "cpe:/a:redhat:openstack:10::el7", "package": "qemu-kvm-rhev-10:2.12.0-18.el7_6.5", "product_name": "Red Hat OpenStack Platform 10.0 (Newton)", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1201", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "qemu-kvm-rhev-10:2.12.0-18.el7_6.5", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1202", "cpe": "cpe:/a:redhat:openstack:14::el7", "package": "qemu-kvm-rhev-10:2.12.0-18.el7_6.5", "product_name": "Red Hat OpenStack Platform 14.0 (Rocky)", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1199", "cpe": "cpe:/a:redhat:openstack:9::el7", "package": "qemu-kvm-rhev-10:2.12.0-18.el7_6.5", "product_name": "Red Hat OpenStack Platform 9.0 (Mitaka)", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1204", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "vdsm-0:4.20.49-1.el7ev", "product_name": "Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1209", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "redhat-release-virtualization-host-0:4.2-8.6.el7", "product_name": "Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1209", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "redhat-virtualization-host-0:4.2-20190512.0.el7_6", "product_name": "Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1179", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "qemu-kvm-rhev-10:2.12.0-18.el7_6.5", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1203", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "vdsm-0:4.30.13-4.el7ev", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1207", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "redhat-release-virtualization-host-0:4.3-0.7.el7", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1207", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "redhat-virtualization-host-0:4.3-20190512.0.el7_6", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1208", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "rhvm-appliance-0:4.3-20190506.0.el7", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:2553", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "qemu-kvm-rhev-10:2.12.0-33.el7", "product_name": "Red Hat Virtualization 4 for Red Hat Enterprise Linux 7", "release_date": "2019-08-22T00:00:00Z"}, {"advisory": "RHSA-2019:1206", "cpe": "cpe:/a:redhat:rhev_manager:4.2", "package": "rhvm-setup-plugins-0:4.2.14-1.el7ev", "product_name": "Red Hat Virtualization Engine 4.2", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:1205", "cpe": "cpe:/a:redhat:rhev_manager:4.3", "package": "rhvm-setup-plugins-0:4.3.1-1.el7ev", "product_name": "Red Hat Virtualization Engine 4.3", "release_date": "2019-05-14T00:00:00Z"}, {"advisory": "RHSA-2019:2553", "cpe": "cpe:/a:redhat:rhev_manager:4.3", "package": "qemu-kvm-rhev-10:2.12.0-33.el7", "product_name": "Red Hat Virtualization Engine 4.3", "release_date": "2019-08-22T00:00:00Z"}], "bugzilla": {"description": "hardware: Microarchitectural Fill Buffer Data Sampling (MFBDS)", "id": "1646784", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1646784"}, "csaw": true, "cvss3": {"cvss3_base_score": "6.2", "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "status": "verified"}, "cwe": "CWE-203->CWE-385->CWE-226", "details": ["Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf", "A flaw was found in the implementation of the \"fill buffer\", a mechanism used by modern CPUs when a cache-miss is made on L1 CPU cache. If an attacker can generate a load operation that would create a page fault, the execution will continue speculatively with incorrect data from the fill buffer while the data is fetched from higher level caches. This response time can be measured to infer data in the fill buffer."], "name": "CVE-2018-12130", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Will not fix", "package_name": "kernel", "product_name": "Red Hat Enterprise Linux 5"}, {"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Not affected", "package_name": "kernel-alt", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/o:redhat:rhev_hypervisor:4", "fix_state": "Affected", "package_name": "ovirt-guest-agent", "product_name": "Red Hat Virtualization 4"}], "public_date": "2019-05-14T17:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2018-12130\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-12130"], "statement": "Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the 'Vulnerability Response' URL.", "threat_severity": "Important"}