Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-28956

Опубликовано: 13 мая 2025
Источник: debian
EPSS Низкий

Описание

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
intel-microcodefixed3.20250512.1package
linuxfixed6.12.29-1package
xenunfixedpackage
xenend-of-lifebullseyepackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-469.html

  • https://www.vusec.net/projects/training-solo/

  • https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/indirect-target-selection.html

  • https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01153.html

  • https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512

EPSS

Процентиль: 2%
0.00016
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 1 месяца назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
redhat
около 1 месяца назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
nvd
около 1 месяца назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

suse-cvrf
27 дней назад

Security update for xen

CVSS3: 5.6
github
около 1 месяца назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

EPSS

Процентиль: 2%
0.00016
Низкий
Уязвимость CVE-2024-28956