Vulnerabilities > CVE-2022-29901 - Exposure of Resource to Wrong Sphere vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://comsec.ethz.ch/retbleed
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00702.html
- http://www.openwall.com/lists/oss-security/2022/07/12/2
- http://www.openwall.com/lists/oss-security/2022/07/12/4
- http://www.openwall.com/lists/oss-security/2022/07/12/5
- http://www.openwall.com/lists/oss-security/2022/07/13/1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M27MB3QFNIJV4EQQSXWARHP3OGX6CR6K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4RW5FCIYFNCQOEFJEUIRW3DGYW7CWBG/
- https://www.debian.org/security/2022/dsa-5207
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.html
- https://security.netapp.com/advisory/ntap-20221007-0007/
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html
- https://www.secpod.com/blog/retbleed-intel-and-amd-processor-information-disclosure-vulnerability/
- https://security.gentoo.org/glsa/202402-07