Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40982

Опубликовано: 08 авг. 2023
Источник: redhat
CVSS3: 6.5

Описание

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors. This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core.

Меры по смягчению последствий

The vulnerability can be mitigated by installing the CPU microcode package microcode_ctl version 20230808.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2023:742421.11.2023
Red Hat Enterprise Linux 7kernelFixedRHSA-2023:742321.11.2023
Red Hat Enterprise Linux 7.7 Advanced Update SupportkernelFixedRHSA-2024:331923.05.2024
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2023:690114.11.2023
Red Hat Enterprise Linux 8kernelFixedRHSA-2023:707714.11.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportkernelFixedRHSA-2024:126812.03.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rtFixedRHSA-2024:126912.03.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicekernelFixedRHSA-2024:126812.03.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionskernelFixedRHSA-2024:126812.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2223949hw: Intel: Gather Data Sampling (GDS) side channel vulnerability

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
nvd
почти 2 года назад

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
debian
почти 2 года назад

Information exposure through microarchitectural state after transient ...

oracle-oval
почти 2 года назад

ELSA-2023-12786: Unbreakable Enterprise kernel-container security update (IMPORTANT)

oracle-oval
почти 2 года назад

ELSA-2023-12785: Unbreakable Enterprise kernel-container security update (IMPORTANT)

6.5 Medium

CVSS3