CVE-2022-26373

MEDIUMCVSS 5.5/10EPSS 0.35%

Last modified

CVE-2022-26373 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.35%

26.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelXeon Platinum 8253 FirmwareAll versions
IntelXeon Platinum 8256 FirmwareAll versions
IntelXeon Platinum 8260 FirmwareAll versions
IntelXeon Platinum 8260l FirmwareAll versions
IntelXeon Platinum 8260m FirmwareAll versions
IntelXeon Platinum 8260y FirmwareAll versions
IntelXeon Platinum 8268 FirmwareAll versions
IntelXeon Platinum 8270 FirmwareAll versions
IntelXeon Platinum 8276 FirmwareAll versions
IntelXeon Platinum 8276l FirmwareAll versions
IntelXeon Platinum 8276m FirmwareAll versions
IntelXeon Platinum 8280 FirmwareAll versions
IntelXeon Platinum 8280l FirmwareAll versions
IntelXeon Platinum 8280m FirmwareAll versions
IntelXeon Platinum 9220 FirmwareAll versions
IntelXeon Platinum 9221 FirmwareAll versions
IntelXeon Platinum 9222 FirmwareAll versions
IntelXeon Platinum 9242 FirmwareAll versions
IntelXeon Platinum 9282 FirmwareAll versions
IntelXeon Gold 5215 FirmwareAll versions
IntelXeon Gold 5215l FirmwareAll versions
IntelXeon Gold 5215m FirmwareAll versions
IntelXeon Gold 5217 FirmwareAll versions
IntelXeon Gold 5218 FirmwareAll versions
IntelXeon Gold 5218b FirmwareAll versions
IntelXeon Gold 5218n FirmwareAll versions
IntelXeon Gold 5218r FirmwareAll versions
IntelXeon Gold 5218t FirmwareAll versions
IntelXeon Gold 5220 FirmwareAll versions
IntelXeon Gold 5220r FirmwareAll versions
IntelXeon Gold 5220s FirmwareAll versions
IntelXeon Gold 5220t FirmwareAll versions
IntelXeon Gold 5222 FirmwareAll versions
IntelXeon Gold 6208u FirmwareAll versions
IntelXeon Gold 6209u FirmwareAll versions
IntelXeon Gold 6210u FirmwareAll versions
IntelXeon Gold 6212u FirmwareAll versions
IntelXeon Gold 6222v FirmwareAll versions
IntelXeon Gold 6226 FirmwareAll versions
IntelXeon Gold 6226r FirmwareAll versions
IntelXeon Gold 6230 FirmwareAll versions
IntelXeon Gold 6230n FirmwareAll versions
IntelXeon Gold 6230r FirmwareAll versions
IntelXeon Gold 6230t FirmwareAll versions
IntelXeon Gold 6234 FirmwareAll versions
IntelXeon Gold 6238 FirmwareAll versions
IntelXeon Gold 6238l FirmwareAll versions
IntelXeon Gold 6238m FirmwareAll versions
IntelXeon Gold 6238r FirmwareAll versions
IntelXeon Gold 6238t FirmwareAll versions

Showing 50 of 492 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-26373?
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
How severe is CVE-2022-26373?
CVE-2022-26373 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2022-26373?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-26373?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST