CVE-2022-29900
Dell ECS: Sicherheitsluecke
Affected
- Dell/ECS
3.8.1.0..*
Description
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Source: BSI CSAFBSI WID Portalcvelistv5
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.0Metrics
90.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
66.16
PoC (publicly reported)
Published
2022-07-12 15:50 UTC
References & sources
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1037
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYI3OMJ7RIZNL3C6GUWNANNPEUUID6FM/vendor-advisory
- https://www.debian.org/security/2022/dsa-5207vendor-advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.htmlmailing-list
- https://www.secpod.com/blog/retbleed-intel-and-amd-processor-information-disclosure-vulnerability/
- https://security.gentoo.org/glsa/202402-07vendor-advisory