CVE-2022-40982

Offenlegung von Informationen durch den Mikroarchitekturzustand nach vorübergehender Ausführung in bestimmten Vektor-Ausführungseinheiten…

mediumEPSS 3.1%

Description

A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors. This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core.

Metrics

6.5
Source: cna-v3
87.2 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
no public PoC known
3.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2023-08-11 02:37 UTC
CWE-1342

Weakness classes (CWE)

  • CWE-1342Base

    Information Exposure through Microarchitectural State after Transient Execution

    The processor does not properly clear microarchitectural state after incorrect microcode assists or speculative execution, resulting in transient execution.

    cwe.mitre.org →

References & sources

Linked advisories