Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23825

Опубликовано: 14 июл. 2022
Источник: debian
EPSS Низкий

Описание

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.16.2-1package
xenpostponedbullseyepackage
xenend-of-lifebusterpackage

Примечания

  • https://comsec.ethz.ch/research/microarch/retbleed/

  • https://comsec.ethz.ch/wp-content/files/retbleed_addendum_sec22.pdf

  • https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1037

  • https://xenbits.xen.org/xsa/advisory-407.html

  • Followup (which did not got a new CVE allocated by AMD):

  • https://xenbits.xen.org/xsa/advisory-422.html

  • https://www.amd.com/system/files/documents/technical-guidance-for-mitigating-branch-type-confusion.pdf

EPSS

Процентиль: 40%
0.00174
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

CVSS3: 5.6
redhat
почти 3 года назад

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

CVSS3: 6.5
nvd
почти 3 года назад

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

msrc
почти 3 года назад

AMD: CVE-2022-23825 AMD CPU Branch Type Confusion

CVSS3: 6.5
github
почти 3 года назад

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

EPSS

Процентиль: 40%
0.00174
Низкий