Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
Loading...
Loading...
Score elevated to 9.0 because EPSS predicts 90% probability of exploitation within the next 30 days (top 0.4% of all CVEs). NVD baseline CVSS 5.6 retained for reference. Confidence: see factors.
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
January 4, 2018
May 28, 2026
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
RHSA-2018:0010 — Important
RHSA-2018:0016 — Important
RHSA-2018:0017 — Important
RHSA-2018:0018 — Important
RHSA-2018:0020 — Important
RHSA-2018:0021 — Important
RHSA-2018:0022 — Important
RHSA-2018:0292 — Important
RHSA-2018:0464 — Important
RHSA-2018:1062 — Important
RHSA-2018:1129 — Important
RHSA-2018:1319 — Important
RHSA-2018:1346 — Important
RHSA-2018:1374 — Important
Firefox vulnerabilities
Linux kernel vulnerability
Linux (Xenial HWE) vulnerability
Linux kernel vulnerabilities
Linux kernel (HWE) vulnerabilities
Linux kernel vulnerability
Linux kernel (Trusty HWE) vulnerability
Linux kernel vulnerability
Linux kernel vulnerabilities
Linux kernel (Xenial HWE) vulnerabilities
Linux kernel vulnerabilities
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (3 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
This tool allows to check speculative execution side-channel attacks that affect many modern processors and operating systems designs. CVE-2017-5754 (Meltdown) and CVE-2017-5715 (Spectre) allows unprivileged processes to steal secrets from privileged processes. These attacks present 3 different ways of attacking data protection measures on CPUs enabling attackers to read data they shouldn't be able to. This tool is originally based on Microsoft: https://support.microsoft.com/en-us/help/4073119/protect-against-speculative-execution-side-channel-vulnerabilities-in
Open source ↗SpecuCheck is a Windows utility for checking the state of the software mitigations and hardware against CVE-2017-5754 (Meltdown), CVE-2017-5715 (Spectre v2), CVE-2018-3260 (Foreshadow), and CVE-2018-3639 (Spectre v4)
Open source ↗Meltdown Exploit / Proof-of-concept / checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.
Open source ↗This CVE was central to one or more publicly-documented breaches. Each card links to authoritative reporting at the time of the incident.
Speculative-execution side-channel attacks against virtually every modern CPU (Intel, AMD, ARM). Required hardware-firmware updates and OS kernel changes across the industry.
Source: ZDNetSee which npm, PyPI, Go, and Maven packages are affected by CVE-2017-5754
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
redhat
CWE-200