cbcvebase.
CVE-2022-40982
published 2023-08-11

CVE-2022-40982: Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an…

PriorityP431medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
3.88%
89.0th percentile
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianintel-microcode< intel-microcode 3.20230808.1~deb12u1 (bookworm)intel-microcode 3.20230808.1~deb12u1 (bookworm)
debianlinux< intel-microcode 3.20230808.1~deb12u1 (bookworm)intel-microcode 3.20230808.1~deb12u1 (bookworm)
googlechrome_chrome
intelmicrocode< 2023080820230808
linuxlinux_kernel>= 0 < 5.10.179-55.10.179-5
linuxlinux_kernel>= 0 < 6.1.38-46.1.38-4
linuxlinux_kernel>= 0 < 6.4.4-36.4.4-3
linuxlinux_kernel>= 0 < 6.4.4-36.4.4-3
linuxlinux_kernel>= 0 < 5.4.0-159.1765.4.0-159.176
linuxlinux_kernel>= 0 < 5.15.0-82.915.15.0-82.91
linuxlinux_kernel>= 0 < 4.4.0-245.2794.4.0-245.279
linuxlinux_kernel>= 0 < 4.15.0-218.2294.15.0-218.229
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.