Red Hat has released a patch for Lazy FPU vulnerabilities and recommends that RHEL 7 series be upgraded as soon as possible.
On June 13, 2018, Intel issued a security announcement that it had discovered a vulnerability in the presumed execution side channel, Lazy FPU, numbered CVE-2018-3665, which could be used to steal sensitive data from CPU's mathematical processing unit. Red Hat immediately issued a security announcement on June 14, saying that security patches had been issued for all affected RHEL 7 series systems and urged users of the affected systems to upgrade immediately.
the systems affected this time include Red Hat Enterprise Linux Server 7, Red Hat Enterprise Linux Server-Extended Update Support 7.5, Red Hat Enterprise Linux Workstation 7, Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux 7 for IBM System z, POWER, ARM64,Red Hat Enterprise Linux for Scientific Computing 7, Red Hat Enterprise Linux EUS Compute Node 7.5 and Red Hat Virtualization Host 4.
the CnetOS Linux 7 distribution, an operating system based on the RHEL 7 series, has also received kernel security updates for "Lazy FPU". Therefore, it is recommended that all CentOS 7 users upgrade to the kernel-3.10.0-862.3.3.el7.x86_64.rpm kernel version immediately. For more information, please check out today's security bulletin.
in today's security bulletin, Red Hat also gave special thanks to Julian Stecklina from Amazon.de, Thomas Prescher from cyberus-technology.de, and Zdenek Sojka from sysgo.com, who discovered this vulnerability.