cbcvebase.
CVE-2022-21123
published 2022-06-15

CVE-2022-21123: Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via…

PriorityP429medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
6.16%
92.7th percentile
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianintel-microcode< intel-microcode 3.20220510.1 (bookworm)intel-microcode 3.20220510.1 (bookworm)
debianlinux< intel-microcode 3.20220510.1 (bookworm)intel-microcode 3.20220510.1 (bookworm)
debianxen< intel-microcode 3.20220510.1 (bookworm)intel-microcode 3.20220510.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
intelsgx_dcap< 1.14.100.31.14.100.3
intelsgx_psw< 2.16.100.32.16.100.3
intelsgx_psw< 2.17.100.32.17.100.3
intelsgx_sdk< 2.16.100.32.16.100.3
intelsgx_sdk< 2.17.100.32.17.100.3
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 4.15.0-187.1984.15.0-187.198
linuxlinux_kernel>= 0 < 5.4.0-120.1365.4.0-120.136
linuxlinux_kernel>= 0 < 5.15.0-39.425.15.0-39.42
linuxlinux_kernel>= 0 < 3.13.0-190.2413.13.0-190.241
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_20h2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5HIGH
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.