cbcvebase.
CVE-2022-29901
published 2022-07-12

CVE-2022-29901: Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary…

medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
intelintel_microprocessors
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 4.15.0-204.2154.15.0-204.215
linuxlinux_kernel>= 0 < 5.4.0-132.1485.4.0-132.148
linuxlinux_kernel>= 0 < 5.15.0-46.495.15.0-46.49
linuxlinux_kernel>= 0 < 4.4.0-242.2764.4.0-242.276
vmwareesxi

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
osv7.8HIGH