CVE-2017-5754: Meltdown
A CPU hardware vulnerability (rogue data cache load) affecting most Intel processors and some ARM designs, where speculative out-of-order execution allows an unprivileged process to read memory it should never be able to access, including kernel memory, by measuring cache-timing side effects left behind by speculatively executed instructions.
View the authoritative record on NVD ↗Affected software
- Most Intel x86 processors manufactured since roughly 1995, and some ARM Cortex-A processors
How it's exploited
Execute an instruction sequence that triggers a speculative, out-of-order read of privileged memory before the CPU's permission check resolves and rolls the result back; use a cache-timing side channel (measuring access latency to indirectly addressed memory) to infer the value that was speculatively read, byte by byte.
Severity
CVE-2017-5754 carries a CVSS 3.1 base score of 5.6, rated Medium. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2017-5754 is categorized under CWE-203, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Apply OS-level kernel page-table isolation (KPTI) patches and CPU microcode updates from the hardware vendor; performance-sensitive workloads may need additional tuning since KPTI carries a measurable overhead.
Frequently asked questions
What is CVE-2017-5754?
A CPU hardware vulnerability (rogue data cache load) affecting most Intel processors and some ARM designs, where speculative out-of-order execution allows an unprivileged process to read memory it should never be able to access, including kernel memory, by measuring cache-timing side effects left behind by speculatively executed instructions.
How severe is CVE-2017-5754?
CVE-2017-5754 has a CVSS 3.1 base score of 5.6 out of 10, rated Medium.
What software is affected by CVE-2017-5754?
CVE-2017-5754 affects Most Intel x86 processors manufactured since roughly 1995, and some ARM Cortex-A processors.
How do you fix CVE-2017-5754?
Apply OS-level kernel page-table isolation (KPTI) patches and CPU microcode updates from the hardware vendor; performance-sensitive workloads may need additional tuning since KPTI carries a measurable overhead.
Where is the authoritative record for CVE-2017-5754?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2017-5754 at https://nvd.nist.gov/vuln/detail/CVE-2017-5754, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest