cbcvebase.
CVE-2022-23825
published 2022-07-14

CVE-2022-23825: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.78%
51.8th percentile
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

Affected

24 ranges
VendorProductVersion rangeFixed in
amdamd_processors
debiandebian_linux
debianxen< xen 4.16.2-1 (bookworm)xen 4.16.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_20h2
msrcwindows_10_version_21h1
msrcwindows_10_version_21h2
msrcwindows_11_version_21h2
msrcwindows_server_2008
msrcwindows_server_2008_r2
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022
vmwareesxi
xenxen>= 0 < 4.14.5+24-g87d90d511c-14.14.5+24-g87d90d511c-1
xenxen>= 0 < 4.16.2-14.16.2-1
xenxen>= 0 < 4.16.2-14.16.2-1
xenxen>= 0 < 4.16.2-14.16.2-1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.