Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28746

Опубликовано: 14 фев. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

A vulnerability was found in some Intel Atom Processor's microcode. This issue may allow a malicious actor to achieve a local information disclosure, impacting the data confidentiality of the targeted system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 6kernel-rtOut of support scope
Red Hat Enterprise Linux 6microcode_ctlOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 7microcode_ctlAffected
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 8microcode_ctlAffected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 8kernelFixedRHSA-2024:510108.08.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1342
https://bugzilla.redhat.com/show_bug.cgi?id=2270700kernel: Local information disclosure on Intel(R) Atom(R) processors

EPSS

Процентиль: 14%
0.00046
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
nvd
больше 1 года назад

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

msrc
больше 1 года назад

Intel: CVE-2023-28746 Register File Data Sampling (RFDS)

CVSS3: 6.5
debian
больше 1 года назад

Information exposure through microarchitectural state after transient ...

CVSS3: 6.5
github
больше 1 года назад

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

EPSS

Процентиль: 14%
0.00046
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2023-28746