CVE-2022-40982

MEDIUM

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS v3.1 Score

6.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Complexity
LOW
Privileges
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Published: 8/11/2023Modified: 6/17/2026

Related Intelligence (1)

References (29)

http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.htmlExploitMitigationhttps://access.redhat.com/solutions/7027704Third Party Advisoryhttps://aws.amazon.com/security/security-bulletins/AWS-2023-007/Third Party Advisoryhttps://downfall.pageExploitTechnical Descriptionhttps://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlMailing ListThird Party Advisoryhttps://lists.debian.org/debian-lts-announce/2023/08/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/https://security.netapp.com/advisory/ntap-20230811-0001/Third Party Advisoryhttps://www.debian.org/security/2023/dsa-5474Mailing ListThird Party Advisoryhttps://www.debian.org/security/2023/dsa-5475Mailing ListThird Party Advisoryhttps://xenbits.xen.org/xsa/advisory-435.htmlMitigationThird Party Advisoryhttp://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.htmlExploitMitigationhttp://xenbits.xen.org/xsa/advisory-435.htmlhttps://access.redhat.com/solutions/7027704Third Party Advisoryhttps://aws.amazon.com/security/security-bulletins/AWS-2023-007/Third Party Advisoryhttps://downfall.pageExploitTechnical Descriptionhttps://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlMailing ListThird Party Advisoryhttps://lists.debian.org/debian-lts-announce/2023/08/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/https://security.netapp.com/advisory/ntap-20230811-0001/Third Party Advisoryhttps://www.debian.org/security/2023/dsa-5474Mailing ListThird Party Advisoryhttps://www.debian.org/security/2023/dsa-5475Mailing ListThird Party Advisoryhttps://xenbits.xen.org/xsa/advisory-435.htmlMitigationThird Party Advisory