---
title: Ubuntu updates to mitigate new Microarchitectural Data Sampling (MDS) vulnerabilities
description: Ubuntu updates to mitigate new Microarchitectural Data Sampling (MDS)
  vulnerabilities covering releases 16.04 LTS, 18.04 LTS, 18.10, 19.04 and 14.04 ESM
url: https://canonical.com/blog/ubuntu-updates-to-mitigate-new-microarchitectural-data-sampling-mds-vulnerabilities?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Alex Murray](https://canonical.com/blog/author/alexmurray "More about Alex Murray")

14 May 2019

# Ubuntu updates to mitigate new Microarchitectural Data Sampling (MDS) vulnerabilities

[14.04](https://canonical.com/blog/tag/14-04)
[16.04](https://canonical.com/blog/tag/16-04)
[18.04](https://canonical.com/blog/tag/18-04)
[ESM](https://canonical.com/blog/tag/esm)
[Extended Security Maintenance](https://canonical.com/blog/tag/extended-security-maintenance)
[Intel](https://canonical.com/blog/tag/intel)
[mds](https://canonical.com/blog/tag/mds)
[Security](https://canonical.com/blog/tag/security)
[Trusty Tahr](https://canonical.com/blog/tag/trusty-tahr)

---

Share the article

Microarchitectural Data Sampling (MDS) describes a group of vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091) in various Intel microprocessors, which allow a malicious process to read various information from another process which is executing on the same CPU core. This occurs due to the use of various microarchitectural elements (buffers) within the CPU core. If one process is able to speculatively sample data from these buffers, it can infer their contents and read data belonging to another process since these buffers are not cleared when switching between processes. This includes switching between two different userspace processes, switching between kernel and userspace and switching between the host and a guest when using virtualisation.

In the case of a single process being scheduled to a single CPU thread, it is relatively simple to mitigate this vulnerability by clearing these buffers when scheduling a new process onto the CPU thread. To achieve this, Intel have released an updated microcode which combined with changes to the Linux kernel ensure these buffers are appropriately cleared.

Updated versions of the *intel-microcode*, *qemu* and *linux* kernel packages are being published as part of the standard Ubuntu security maintenance of Ubuntu releases 16.04 LTS, 18.04 LTS, 18.10, 19.04 and as part of the extended security maintenance for [Ubuntu 14.04 ESM](https://www.ubuntu.com/esm) users. As these vulnerabilities affect such a large range of Intel processors (across laptop, desktop and server machines), a large percentage of Ubuntu users are expected to be impacted – users are encouraged to install these updated packages as soon as they become available.

The use of Symmetric Multi-Threading (SMT) – also known as Hyper-Threading – further complicates these issues since these buffers are shared between sibling Hyper-Threads. Therefore, the above changes are not sufficient to mitigate these vulnerabilities when SMT is enabled. As such, the use of SMT is not recommended when untrusted code or applications are being executed.

For further details, including the specific package versions that mitigate these vulnerablities and instructions for optionally disabling SMT, please consult [this article](https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/MDS) within the Ubuntu Security Knowledge Base.

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
