CVE-2022-29901

Advisory lineage Upstream: 0 Downstream: 57
Modified
Published: 12 Jul 2022, 00:00
Last modified:03 Aug 2024, 06:33

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Jul 2022, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 06:33
Last Modified
Vulnerability information updated

Description

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Techniques & Countermeasures

  • CWE-668Exposure of Resource to Wrong Sphere

    The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • debiandebian_linux

    10.0 | 11.0

  • fedoraprojectfedora

    35 | 36

  • intelcore_i3-6100_firmware

    na

  • intelcore_i3-6100e_firmware

    na

  • intelcore_i3-6100h_firmware

    na

  • intelcore_i3-6100t_firmware

    na

  • intelcore_i3-6100te_firmware

    na

  • intelcore_i3-6100u_firmware

    na

  • intelcore_i3-6102e_firmware

    na

  • intelcore_i3-6110u_firmware

    na

  • intelcore_i3-6120_firmware

    na

  • intelcore_i3-6120t_firmware

    na

  • intelcore_i3-6167u_firmware

    na

  • intelcore_i3-6300_firmware

    na

  • intelcore_i3-6300t_firmware

    na

  • intelcore_i3-6320_firmware

    na

  • intelcore_i3-6320t_firmware

    na

  • intelcore_i3-8000_firmware

    na

  • intelcore_i3-8000t_firmware

    na

  • intelcore_i3-8020_firmware

    na

  • intelcore_i3-8100_firmware

    na

  • intelcore_i3-8100h_firmware

    na

  • intelcore_i3-8100t_firmware

    na

  • intelcore_i3-8109u_firmware

    na

  • intelcore_i3-8120_firmware

    na

  • intelcore_i3-8130u_firmware

    na

  • intelcore_i3-8145u_firmware

    na

  • intelcore_i3-8300_firmware

    na

  • intelcore_i3-8300t_firmware

    na

  • intelcore_i3-8350k_firmware

    na

  • intelcore_i5-6200u_firmware

    na

  • intelcore_i5-6210u_firmware

    na

  • intelcore_i5-6260u_firmware

    na

  • intelcore_i5-6267u_firmware

    na

  • intelcore_i5-6287u_firmware

    na

  • intelcore_i5-6300hq_firmware

    na

  • intelcore_i5-6300u_firmware

    na

  • intelcore_i5-6310u_firmware

    na

  • intelcore_i5-6350hq_firmware

    na

  • intelcore_i5-6360u_firmware

    na

  • intelcore_i5-6400_firmware

    na

  • intelcore_i5-6400t_firmware

    na

  • intelcore_i5-6440eq_firmware

    na

  • intelcore_i5-6440hq_firmware

    na

  • intelcore_i5-6442eq_firmware

    na

  • intelcore_i5-6500_firmware

    na

  • intelcore_i5-6500t_firmware

    na

  • intelcore_i5-6500te_firmware

    na

  • intelcore_i5-6600_firmware

    na

  • intelcore_i5-6600k_firmware

    na

Showing first 50 affected entries in server-rendered view.

References (14)