Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55c8-6r36-9g85

Опубликовано: 13 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

EPSS

Процентиль: 24%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-668

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 3 года назад

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 5.6
redhat
почти 3 года назад

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 5.6
nvd
почти 3 года назад

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 5.6
debian
почти 3 года назад

Intel microprocessor generations 6 to 8 are affected by a new Spectre ...

CVSS3: 5.6
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения процессоров Intel и AMD, позволяющая нарушителю раскрыть защищаемую информацию из памяти ядра или осуществить атаку на хост-систему из виртуальных машин

EPSS

Процентиль: 24%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-668