Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-3665

20
FAUCET Score

CVE-2018-3665 is a medium-severity vulnerability affecting Intel Core-based microprocessors, where system software using Lazy FP state restore can allow a local process to infer data from another via a speculative execution side channel. The attack requires low privileges and high attack complexity, but can lead to high confidentiality impact. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
330eCPE matchmatch criteria
cpe:2.3:h:intel:core_i3:330e:*:*:*:*:*:*:*
330mCPE matchmatch criteria
cpe:2.3:h:intel:core_i3:330m:*:*:*:*:*:*:*
330umCPE matchmatch criteria
cpe:2.3:h:intel:core_i3:330um:*:*:*:*:*:*:*
350mCPE matchmatch criteria
cpe:2.3:h:intel:core_i3:350m:*:*:*:*:*:*:*
370mCPE matchmatch criteria
cpe:2.3:h:intel:core_i3:370m:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.6MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0061 is in the 88th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-754.2.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-862.3.3.rt56.809.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-862.3.3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Extended Update SupportFixed in: kernel-0:3.10.0-693.47.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.35.1.rt56.625.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.47.2.rt56.641.el6rt
View patch

Vendor Advisories (1)

redhatCVE-2018-3665Moderate

Kernel: FPU state information leakage via lazy FPU restore

Jun 13, 2018

References

access.redhat.com / errata/RHSA-2018:1852
Third Party Advisory
access.redhat.com / errata/RHSA-2018:1944
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2164
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2165
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1170
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1190
Third Party Advisory
help.ecostruxureit.com / display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
Third Party Advisory
lists.debian.org / debian-lts-announce/2018/07/msg00015.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2018/07/msg00016.html
Third Party Advisory
nvidia.custhelp.com / app/answers/detail/a_id/4787
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-18:07.lazyfpu.asc
Third Party Advisory
security.netapp.com / advisory/ntap-20181016-0001
Third Party Advisory
security.paloaltonetworks.com / CVE-2018-3665
Third Party Advisory
support.citrix.com / article/CTX235745
Third Party Advisory
usn.ubuntu.com / 3696-1
Third Party Advisory
usn.ubuntu.com / 3696-2
Third Party Advisory
usn.ubuntu.com / 3698-1
Third Party Advisory
usn.ubuntu.com / 3698-2
Third Party Advisory
debian.org / security/2018/dsa-4232
Third Party Advisory
intel.com / content/www/us/en/security-center/advisory/intel-sa-00145.html
Vendor Advisory
oracle.com / security-alerts/cpujul2020.html
Third Party Advisory
synology.com / support/security/Synology_SA_18_31
Third Party Advisory
securityfocus.com / bid/104460
Third Party AdvisoryVDB Entry
securitytracker.com / id/1041124
Third Party AdvisoryVDB Entry
securitytracker.com / id/1041125
Third Party AdvisoryVDB Entry