Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-21166

Опубликовано: 15 июн. 2022
Источник: debian

Описание

Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
intel-microcodefixed3.20220510.1package
intel-microcodeno-dsabullseyepackage
linuxfixed5.18.5-1package
linuxfixed5.10.127-1bullseyepackage
xenfixed4.16.2-1package
xenend-of-lifebusterpackage

Примечания

  • https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html

  • https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/processor-mmio-stale-data-vulnerabilities.html#DRPW

  • Linux kernel documentation patch: https://git.kernel.org/linus/4419470191386456e0b8ed4eb06a70b0021798a6

  • https://xenbits.xen.org/xsa/advisory-404.html

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
redhat
около 3 лет назад

Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
nvd
около 3 лет назад

Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

msrc
около 3 лет назад

Intel: CVE-2022-21166 Device Register Partial Write (DRPW)

CVSS3: 5.5
fstec
около 3 лет назад

Уязвимость набора средств разработки Intel Software Guard Extensions SDK, микропрограммного обеспечения Intel SGX DCAP, SGX PSW, PSW связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю раскрыть защищаемую информацию