CVE-2022-26373Sensitive Information Exposure in Linux

Severity
5.5MEDIUMNVD
OSV7.8OSV6.7OSV4.7OSV4.4
EPSS
0.1%
top 71.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateJul 12

Description

Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/linux< linux 5.18.16-1 (bookworm)
Debianlinux/linux_kernel< 5.10.136-1+3
Ubuntulinux/linux_kernel< 4.15.0-204.215+3

Also affects: Debian Linux 10.0

🔴Vulnerability Details

18
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2023-07-12
OSV
linux-gcp vulnerabilities2023-04-11
OSV
linux-azure vulnerabilities2023-03-27
OSV
linux-azure, linux-azure, linux-azure vulnerabilities2023-03-06
OSV
linux-hwe vulnerabilities2023-02-22

📋Vendor Advisories

20
Ubuntu
Linux kernel vulnerabilities2023-07-12
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Ubuntu
Linux kernel (GCP) vulnerabilities2023-04-11
Ubuntu
Linux kernel vulnerabilities2023-03-27
Ubuntu
Linux kernel (Azure) vulnerabilities2023-03-06