Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3p5-98fc-2gxr

Опубликовано: 13 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

AMD microprocessor families 15h to 18h are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

AMD microprocessor families 15h to 18h are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

EPSS

Процентиль: 80%
0.01415
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-212

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 5.6
redhat
около 3 лет назад

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 6.5
nvd
около 3 лет назад

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

msrc
около 3 лет назад

AMD: CVE-2022-29900 AMD CPU Branch Type Confusion

CVSS3: 6.5
debian
около 3 лет назад

Mis-trained branch predictions for return instructions may allow arbit ...

EPSS

Процентиль: 80%
0.01415
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-212