← Vulnerability feed

Vulnerability record · CVE-2018-3639 · published 22 May 2018

CVE-2018-3639: Intel microprocessors speculative store bypass side-channel info disclosure

Intel · Atom C

CVE-2018-3639 is the Speculative Store Bypass (SSB) side-channel flaw, also called Variant 4, affecting Intel microprocessors that use speculative execution. A local attacker can observe timing differences to infer data that should not be readable, leaking information across privilege boundaries. It matters because the affected product list is broad and the flaw is a hardware design issue requiring microcode and OS-level fixes.

5.5 CVSS 3.1 Medium EPSS 61% · top 0.9% CWE-203 · Observable discrepancy
5.5CVSS 3.1 base score, v2 2.1
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
294References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS is medium (5.5) and exploitation requires local access, but the affected Intel product range is broad and EPSS is high.

What it is

CVE-2018-3639 is the Speculative Store Bypass (SSB) side-channel flaw, also called Variant 4, affecting Intel microprocessors that use speculative execution. A local attacker can observe timing differences to infer data that should not be readable, leaking information across privilege boundaries. It matters because the affected product list is broad and the flaw is a hardware design issue requiring microcode and OS-level fixes.

Impact

An attacker with local user access can disclose information from memory they are not authorized to read, via side-channel analysis. The CVSS vector shows confidentiality impact only, with no integrity or availability effect.

Attack surface

Reached locally on the affected system; the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs local user access but no user interaction. No network vector is described.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at 0.60631 (99.1st percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory and mailing-list entries, with no exploit tag present.

What to do

  • Apply Intel microcode updates and the corresponding operating system, hypervisor and firmware patches for Speculative Store Bypass.
  • Enable the SSB mitigation controls provided by the OS or hypervisor where available.
  • Restrict local interactive access and limit untrusted code execution on affected hosts.
  • Track vendor advisories from Red Hat, Lenovo, Fujitsu and Xen for the specific affected platforms.
  • Retire or isolate systems that cannot receive microcode or OS mitigations.

Detection

  • Monitor for local exploitation tooling or proof-of-concept code targeting speculative execution side channels.
  • Audit hosts for missing microcode or kernel patches associated with Speculative Store Bypass.
  • Review local user access and process execution on systems with sensitive data and affected CPUs.
  • Correlate unusual local timing or cache-probing behavior with suspicious process activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html Broken Link
http://support.lenovo.com/us/en/solutions/LEN-22133 Third Party Advisory
http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.html Third Party Advisory
http://www.openwall.com/lists/oss-security/2020/06/10/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/06/10/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/06/10/5 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/104232 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040949 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042004 Third Party AdvisoryVDB Entry
http://xenbits.xen.org/xsa/advisory-263.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1629 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1630 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1632 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1633 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1635 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1636 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1637 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1638 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1639 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1640 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1641 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1642 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1643 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1644 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1645 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1646 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1647 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1648 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1649 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1650 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1651 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1652 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1653 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1654 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1655 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1656 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1657 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1658 Third Party Advisory

Track CVE-2018-3639 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-24489Intel atom x5-e3930 vulnerabilityIncomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.EPSS 0.35%7.8CVE-2020-0559Intel ac 3165 firmware incorrect permission assignment vulnerabilityInsecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticat…EPSS 0.29%7.6CVE-2018-3652Intel xeon e3 information exposure vulnerabilityExisting UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable p…EPSS 0.37%6.8CVE-2021-33150Intel atom c2308 vulnerabilityHardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potenti…EPSS 0.35%6.5CVE-2022-0002Intel atom c3308 vulnerabilityNon-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable informati…EPSS 0.45%6.0CVE-2017-5703Intel core i7-8550u improper privilege management vulnerabilityConfiguration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially l…EPSS 0.34%5.6CVE-2018-3693Intel atom c vulnerabilitySystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…EPSS 8.6%5.6CVE-2018-3640Intel atom c observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure…EPSS 7.6%

Source: NIST National Vulnerability Database (record CVE-2018-3639), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.