cbcvebase.
CVE-2022-27672
published 2023-03-01

CVE-2022-27672: When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially…

medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
amd1st_gen_amd_epyc_processors
amd2nd_gen_amd_epyc_processors
amd2nd_gen_amd_ryzen_threadripper_processors
amd3rd_gen_amd_ryzen_threadripper_processors
amd7th_generation_amd_a-series_apus
amdathlon_mobile_processors
amdathlon_x4_processor
amdryzen_2000_series_processors
amdryzen_3000_series_processors
amdryzen_4000_series_processors
amdryzen_5000_series_processors
amdryzen_threadripper_pro_processor
debianlinux< linux 6.1.12-1 (bookworm)linux 6.1.12-1 (bookworm)
debianxen< linux 6.1.12-1 (bookworm)linux 6.1.12-1 (bookworm)
linuxlinux_kernel>= 0 < 6.1.12-16.1.12-1
linuxlinux_kernel>= 0 < 6.1.12-16.1.12-1
linuxlinux_kernel>= 0 < 6.1.12-16.1.12-1
linuxlinux_kernel>= 0 < 5.4.0-156.1735.4.0-156.173
linuxlinux_kernel>= 0 < 5.15.0-72.795.15.0-72.79
linuxlinux_kernel>= 0 < 4.15.0-218.2294.15.0-218.229
xenxen>= 0 < 4.16.4-r04.16.4-r0
xenxen>= 0 < 4.16.4-r04.16.4-r0
xenxen>= 0 < 4.17.0-r24.17.0-r2
xenxen>= 0 < 4.17.0-r24.17.0-r2
xenxen>= 0 < 4.17.0-r24.17.0-r2

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH