CVE-2022-23825
published 2022-07-14CVE-2022-23825: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.78%
51.8th percentile
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_processors | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.16.2-1 (bookworm) | xen 4.16.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| vmware | esxi | — | — |
| xen | xen | >= 0 < 4.14.5+24-g87d90d511c-1 | 4.14.5+24-g87d90d511c-1 |
| xen | xen | >= 0 < 4.16.2-1 | 4.16.2-1 |
| xen | xen | >= 0 < 4.16.2-1 | 4.16.2-1 |
| xen | xen | >= 0 < 4.16.2-1 | 4.16.2-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi addresses Return-Stack-Buffer-Underflow and Branch Type Confusion vulnerabilities
vendor_vmware·2022-07-12·CVSS 6.5
CVE-2022-23816 [MEDIUM] VMware ESXi addresses Return-Stack-Buffer-Underflow and Branch Type Confusion vulnerabilities
VMSA-2022-0020: VMware ESXi addresses Return-Stack-Buffer-Underflow and Branch Type Confusion vulnerabilities
VMware ESXi contains Return-Stack-Buffer-Underflow (CVE-2022-29901, CVE-2022-28693, CVE-2022-26373) and Branch Type Confusion (CVE-2022-23816, CVE-2022-23825) vulnerabilities due to the Intel and AMD processors it utilizes. VMware has evaluated the severity of these issues to be in the Moderate severity range with a maximum CVSSv3 base score of 5.6.
CVEs: CVE-2022-23816, CVE-2022-23825, CVE-2022-26373, CVE-2022-28693, CVE-2022-29901
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vSphere
Red Hat
hw: cpu: AMD: Branch Type Confusion (non-retbleed)
vendor_redhat·2022-07-12·CVSS 6.5
CVE-2022-23825 [MEDIUM] CWE-200 hw: cpu: AMD: Branch Type Confusion (non-retbleed)
hw: cpu: AMD: Branch Type Confusion (non-retbleed)
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
A flaw was found in hw. Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type, potentially leading to information disclosure.
Package: kernel (Red Hat Enterprise Linux 6) - Will not fix
Microsoft
AMD: CVE-2022-23825 AMD CPU Branch Type Confusion
vendor_msrc·2022-07-12·CVSS 6.5
CVE-2022-23825 [MEDIUM] AMD: CVE-2022-23825 AMD CPU Branch Type Confusion
AMD: CVE-2022-23825 AMD CPU Branch Type Confusion
FAQ: Why is this AMD CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in certain processor models offered by AMD. The mitigation for this vulnerability requires a Windows update. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and provide protection against the vulnerability.
Please see the following for more information:
AMD-SB-1037
FAQ: Are any additional steps required to protect my system after installing the July Windows updates?
Customers who allow untrusted users to execute arbitrary code might wish to implement some extra security features within their systems. These features protect against the intra-process disclos
Debian
CVE-2022-23825: xen - Aliases in the branch predictor may cause some AMD processors to predict the wro...
vendor_debian·2022·CVSS 6.5
CVE-2022-23825 [MEDIUM] CVE-2022-23825: xen - Aliases in the branch predictor may cause some AMD processors to predict the wro...
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
Scope: local
bookworm: resolved (fixed in 4.16.2-1)
bullseye: resolved (fixed in 4.14.5+24-g87d90d511c-1)
forky: resolved (fixed in 4.16.2-1)
sid: resolved (fixed in 4.16.2-1)
trixie: resolved (fixed in 4.16.2-1)
GHSA
GHSA-w7j2-r4x6-6frw: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure
ghsa_unreviewed·2022-07-15
CVE-2022-23825 [MEDIUM] CWE-668 GHSA-w7j2-r4x6-6frw: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
OSV
CVE-2022-23825: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure
osv·2022-07-14·CVSS 6.5
CVE-2022-23825 [MEDIUM] CVE-2022-23825: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/11/08/1http://www.openwall.com/lists/oss-security/2022/11/10/2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4RW5FCIYFNCQOEFJEUIRW3DGYW7CWBG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLSRW4LLTAT3CZMOYVNTC7YIYGX3KLED/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M27MB3QFNIJV4EQQSXWARHP3OGX6CR6K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYI3OMJ7RIZNL3C6GUWNANNPEUUID6FM/https://security.gentoo.org/glsa/202402-07https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1037https://www.debian.org/security/2022/dsa-5184http://www.openwall.com/lists/oss-security/2022/11/08/1http://www.openwall.com/lists/oss-security/2022/11/10/2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4RW5FCIYFNCQOEFJEUIRW3DGYW7CWBG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLSRW4LLTAT3CZMOYVNTC7YIYGX3KLED/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M27MB3QFNIJV4EQQSXWARHP3OGX6CR6K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYI3OMJ7RIZNL3C6GUWNANNPEUUID6FM/https://security.gentoo.org/glsa/202402-07https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1037https://www.debian.org/security/2022/dsa-5184
2022-07-14
Published