CVE-2022-27672
Aliases:UBUNTU-CVE-2022-27672DEBIAN-CVE-2022-27672ALPINE-CVE-2022-27672
Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 14 Feb 2023, 19:34
Last modified:13 Apr 2026, 19:53
Vulnerability Summary
Overall Risk (default)
low
19/100 CVSS Score
4.7 MEDIUM
v3.1 (nvd)
EPSS Score
0.29% LOW
0% probability +0.18%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
14 Feb 2023, 19:34
Published
Vulnerability first disclosed
13 Apr 2026, 19:53
Last Modified
Vulnerability information updated
Description
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.29%• Percentile: 21%
Affected Systems
- amd•1st gen amd epyc™ processors
All versions | Contact your OS vendor
- amd•2nd gen amd epyc™ processors
All versions | Contact your OS vendor
- amd•2nd gen amd ryzen™ threadripper™ processors
All versions | Contact your OS vendor
- amd•3rd gen amd ryzen™ threadripper™ processors
All versions | Contact your OS vendor
- amd•7th generation amd a-series apus
All versions | Contact your OS vendor
- amd•a10-9600p_firmware
na
- amd•a10-9630p_firmware
na
- amd•a12-9700p_firmware
na
- amd•a12-9730p_firmware
na
- amd•a4-9120_firmware
na
- amd•a4-9120c_firmware
na
- amd•a6-9210_firmware
na
- amd•a6-9220_firmware
na
- amd•a6-9220c_firmware
na
- amd•a9-9410_firmware
na
- amd•a9-9420_firmware
na
- amd•athlon_gold_3150c_firmware
na
- amd•athlon_gold_3150u_firmware
na
- amd•athlon_gold_7220u_firmware
na
- amd•athlon_pro_300u_firmware
na
- amd•athlon_pro_3045b_firmware
na
- amd•athlon_pro_3145b_firmware
na
- amd•athlon_silver_3050c_firmware
na
- amd•athlon_silver_3050e_firmware
na
- amd•athlon_silver_3050u_firmware
na
- amd•athlon_silver_7120u_firmware
na
- amd•athlon_x4_750_firmware
na
- amd•athlon_x4_760k_firmware
na
- amd•athlon_x4_830_firmware
na
- amd•athlon_x4_835_firmware
na
- amd•athlon_x4_840_firmware
na
- amd•athlon_x4_845_firmware
na
- amd•athlon_x4_860k_firmware
na
- amd•athlon_x4_870k_firmware
na
- amd•athlon_x4_880k_firmware
na
- amd•athlon_x4_940_firmware
na
- amd•athlon_x4_950_firmware
na
- amd•athlon_x4_970_firmware
na
- amd•athlon™ mobile processors
All versions | Contact your OS vendor
- amd•athlon™ x4 processor
All versions | Contact your OS vendor
- amd•epyc_7232p_firmware
na
- amd•epyc_7252_firmware
na
- amd•epyc_7262_firmware
na
- amd•epyc_7272_firmware
na
- amd•epyc_7282_firmware
na
- amd•epyc_7302_firmware
na
- amd•epyc_7302p_firmware
na
- amd•epyc_7352_firmware
na
- amd•epyc_7402_firmware
na
- amd•epyc_7402p_firmware
na
Showing first 50 affected entries in server-rendered view.
References (30)
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1045
- https://security.gentoo.org/glsa/202402-07
- http://xenbits.xen.org/xsa/advisory-426.html
- https://ubuntu.com/security/CVE-2022-27672
- https://www.openwall.com/lists/oss-security/2023/02/14/4
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1045
- https://xenbits.xen.org/xsa/advisory-426.html
- https://kernel.org/doc/html//next/admin-guide/hw-vuln/cross-thread-rsb.html
- https://ubuntu.com/security/notices/USN-5978-1
- https://ubuntu.com/security/notices/USN-6079-1
- https://ubuntu.com/security/notices/USN-6080-1
- https://ubuntu.com/security/notices/USN-6085-1
- https://ubuntu.com/security/notices/USN-6090-1
- https://ubuntu.com/security/notices/USN-6091-1
- https://ubuntu.com/security/notices/USN-6096-1
- https://ubuntu.com/security/notices/USN-6133-1
- https://ubuntu.com/security/notices/USN-6134-1
- https://ubuntu.com/security/notices/USN-6284-1
- https://ubuntu.com/security/notices/USN-6301-1
- https://ubuntu.com/security/notices/USN-6312-1
- https://ubuntu.com/security/notices/USN-6314-1
- https://ubuntu.com/security/notices/USN-6331-1
- https://ubuntu.com/security/notices/USN-6337-1
- https://ubuntu.com/security/notices/USN-6385-1
- https://ubuntu.com/security/notices/USN-6396-1
- https://ubuntu.com/security/notices/USN-6396-2
- https://ubuntu.com/security/notices/USN-6396-3
- https://www.cve.org/CVERecord?id=CVE-2022-27672
- https://security-tracker.debian.org/tracker/CVE-2022-27672
- https://security.alpinelinux.org/vuln/CVE-2022-27672