Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-28956

Опубликовано: 13 мая 2025
Источник: debian
EPSS Низкий

Описание

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
intel-microcodefixed3.20250512.1package
linuxfixed6.12.29-1package
xenfixed4.20.2+7-g1badcf5035-1package
xenend-of-lifebullseyepackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-469.html

  • https://www.vusec.net/projects/training-solo/

  • https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/indirect-target-selection.html

  • https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01153.html

  • https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512

EPSS

Процентиль: 27%
0.00349
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 1 года назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
redhat
около 1 года назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
nvd
около 1 года назад

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

suse-cvrf
около 1 года назад

Security update for xen

suse-cvrf
около 1 года назад

Security update for xen

EPSS

Процентиль: 27%
0.00349
Низкий