FlawAtlas
Search the atlas
UBUNTU-CVE-2019-1125 Moderate

UBUNTU-CVE-2019-1125

An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a security update on July 9, 2019 that addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. Note that this vulnerability does not require a microcode update from your device OEM.

Exploit probability Not scored
Published August 6, 2019
Required by Not available
Last source change August 18, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux-kvm

27 explicit affected versions

Ubuntu:18.04:LTS linux-gke-4.15

6 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:Pro:14.04:LTS linux

191 explicit affected versions

Ubuntu:18.04:LTS linux-aws

28 explicit affected versions

Ubuntu:18.04:LTS linux-oracle

10 explicit affected versions

Ubuntu:18.04:LTS linux

33 explicit affected versions

Ubuntu:Pro:FIPS:18.04:LTS linux-gcp-fips

1 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:16.04:LTS linux-kvm

33 explicit affected versions

Ubuntu:18.04:LTS linux-gke-5.0

1 explicit affected versions

Ubuntu:18.04:LTS linux-oem

23 explicit affected versions

Ubuntu:18.04:LTS linux-oem-osp1

3 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-azure-fde-5.15

57 explicit affected versions

Ubuntu:18.04:LTS linux-hwe-edge

10 explicit affected versions

Ubuntu:16.04:LTS linux-oracle

10 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-aws

34 explicit affected versions

Ubuntu:Nvidia-BlueField:24.04:LTS linux-bluefield

11 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

34 explicit affected versions

Ubuntu:16.04:LTS linux

95 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:16.04:LTS linux-azure

41 explicit affected versions

Ubuntu:Pro:FIPS:18.04:LTS linux-aws-fips

1 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS linux-aws-fips

1 explicit affected versions

Ubuntu:16.04:LTS linux-aws

54 explicit affected versions

Ubuntu:16.04:LTS linux-aws-hwe

11 explicit affected versions

Ubuntu:18.04:LTS linux-azure

30 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:18.04:LTS linux-gcp

26 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-lts-xenial

75 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

54 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS linux-fips

9 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-azure

21 explicit affected versions

Ubuntu:18.04:LTS linux-hwe

12 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-1125

An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a security update on July 9, 2019 that addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. Note that this vulnerability does not require a microcode update from your device OEM.

View original source

05 / REFERENCES

Further evidence