CVE-2022-21166
Vulnerability Summary
Timeline
Description
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVSS Metrics
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 5.78%• Percentile: 93%
Techniques & Countermeasures
- CWE-459•Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Affected Systems
- alpine•xen
< 4.14.5-r2 | < 4.15.2-r2 | < 4.15.2-r2 | < 4.16.1-r2 | < 4.16.1-r3 | < 4.16.1-r3 | < 4.16.1-r3 | < 4.16.1-r3 | < 4.16.1-r3 | < 4.16.1-r3 | < 4.16.1-r3 | < 4.16.1-r3
- debian•intel-microcode
< 3.20220510.1~deb11u1 | < 3.20220510.1 | < 3.20220510.1 | < 3.20220510.1
- debian•linux
< 5.10.127-1 | < 5.18.5-1 | < 5.18.5-1 | < 5.18.5-1
- debian•xen
< 4.14.5+24-g87d90d511c-1 | < 4.16.2-1 | < 4.16.2-1 | < 4.16.2-1
- ubuntu•intel-microcode
all | < 3.20220510.0ubuntu0.16.04.1+esm1 | < 3.20220510.0ubuntu0.18.04.1 | < 3.20220510.0ubuntu0.20.04.1 | < 3.20220510.0ubuntu0.22.04.1
- ubuntu•linux
all | < 4.4.0-229.263 | < 4.15.0-187.198 | < 5.4.0-120.136 | < 5.15.0-39.42
- ubuntu•linux-aws
< 4.4.0-1109.115 | < 4.4.0-1145.160 | < 4.15.0-1136.147 | < 5.4.0-1080.87 | < 5.15.0-1013.17
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
< 5.13.0-1031.35~20.04.1
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1080.87~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-fips
< 4.15.0-2075.80 | all | < 5.4.0-1080.87+fips1
- ubuntu•linux-aws-hwe
< 4.15.0-1136.147~16.04.1
- ubuntu•linux-azure
< 4.15.0-1145.160~14.04.1 | < 4.15.0-1145.160~16.04.1 | < 5.4.0-1085.90 | < 5.15.0-1012.15 | all
- ubuntu•linux-azure-4.15
< 4.15.0-1145.160
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
< 5.13.0-1031.37~20.04.1
- ubuntu•linux-azure-5.15
< 5.15.0-1014.17~20.04.1
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1085.90~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2056.62 | all | < 5.4.0-1085.90+fips1
- ubuntu•linux-bluefield
all
- ubuntu•linux-dell300x
< 4.15.0-1048.53
- ubuntu•linux-fips
< 4.4.0-1079.86 | all | < 4.15.0-1093.104 | < 5.4.0-1056.64
- ubuntu•linux-gcp
< 4.15.0-1130.146~16.04.1 | < 5.4.0-1080.87 | < 5.15.0-1010.15 | all
- ubuntu•linux-gcp-4.15
< 4.15.0-1130.146
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
< 5.13.0-1033.40~20.04.1
- ubuntu•linux-gcp-5.15
< 5.15.0-1013.18~20.04.1
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1080.87~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-fips
< 4.15.0-2040.45 | all | < 5.4.0-1080.87+fips1
- ubuntu•linux-gke
< 5.15.0-1010.13 | < 5.4.0-1076.82
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
< 5.4.0-1076.82~18.04.1
- ubuntu•linux-gkeop
< 5.4.0-1048.51
- ubuntu•linux-gkeop-5.4
< 5.4.0-1048.51~18.04.1
- ubuntu•linux-hwe
< 4.15.0-187.198~16.04.1 | all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.13
< 5.13.0-51.58~20.04.1
- ubuntu•linux-hwe-5.15
< 5.15.0-41.44~20.04.1
- ubuntu•linux-hwe-5.4
< 5.4.0-120.136~18.04.1
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all | all
Showing first 50 affected entries in server-rendered view.
References (26)
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html
- http://www.openwall.com/lists/oss-security/2022/06/16/1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4P2KJYL74KGLHE4JZETVW7PZH6ZIABA/
- https://security.netapp.com/advisory/ntap-20220624-0008/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MCVOMHBQRH4KP7IN6U24CW7F2D2L5KBS/
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
- https://www.debian.org/security/2022/dsa-5173
- https://www.debian.org/security/2022/dsa-5178
- https://www.debian.org/security/2022/dsa-5184
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q/
- https://security.gentoo.org/glsa/202208-23
- https://ubuntu.com/security/CVE-2022-21166
- https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/processor-mmio-stale-data-vulnerabilities.html#DRPW
- https://xenbits.xen.org/xsa/advisory-404.html
- https://ubuntu.com/security/notices/USN-5484-1
- https://ubuntu.com/security/notices/USN-5485-1
- https://ubuntu.com/security/notices/USN-5486-1
- https://ubuntu.com/security/notices/USN-5485-2
- https://ubuntu.com/security/notices/USN-5505-1
- https://ubuntu.com/security/notices/USN-5513-1
- https://ubuntu.com/security/notices/USN-5529-1
- https://ubuntu.com/security/notices/USN-5535-1
- https://www.cve.org/CVERecord?id=CVE-2022-21166
- https://security-tracker.debian.org/tracker/CVE-2022-21166
- https://security.alpinelinux.org/vuln/CVE-2022-21166