CVE-2022-40982
Offenlegung von Informationen durch den Mikroarchitekturzustand nach vorübergehender Ausführung in bestimmten Vektor-Ausführungseinheiten…
mediumEPSS 3.1%
Description
A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors. This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core.
Source: redhat_csafsuse_csafcvelistv5
Metrics
87.2 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
96.62
no public PoC known
6.5
Published
2023-08-11 02:37 UTC
CWE-1342
Weakness classes (CWE)
CWE-1342Base
Information Exposure through Microarchitectural State after Transient Execution
The processor does not properly clear microarchitectural state after incorrect microcode assists or speculative execution, resulting in transient execution.
cwe.mitre.org →
References & sources
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html
- https://downfall.page
- https://aws.amazon.com/security/security-bulletins/AWS-2023-007/
- https://access.redhat.com/solutions/7027704
- https://xenbits.xen.org/xsa/advisory-435.html
- https://lists.debian.org/debian-lts-announce/2023/08/msg00013.html
- https://security.netapp.com/advisory/ntap-20230811-0001/
- https://www.debian.org/security/2023/dsa-5474
- https://www.debian.org/security/2023/dsa-5475
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/
- https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/
- http://xenbits.xen.org/xsa/advisory-435.html