CVE-2022-29901
Last modified
CVE-2022-29901 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.. EPSS estimates a 4.95% chance of exploitation in the next 30 days.
Description
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Core I7-6500u Firmware | All versions |
| Intel | Core I7-6510u Firmware | All versions |
| Intel | Core I7-6560u Firmware | All versions |
| Intel | Core I7-6567u Firmware | All versions |
| Intel | Core I7-6600u Firmware | All versions |
| Intel | Core I7-6650u Firmware | All versions |
| Intel | Core I7-6660u Firmware | All versions |
| Intel | Core I7-6700 Firmware | All versions |
| Intel | Core I7-6700hq Firmware | All versions |
| Intel | Core I7-6700k Firmware | All versions |
| Intel | Core I7-6700t Firmware | All versions |
| Intel | Core I7-6700te Firmware | All versions |
| Intel | Core I7-6770hq Firmware | All versions |
| Intel | Core I7-6820eq Firmware | All versions |
| Intel | Core I7-6820hk Firmware | All versions |
| Intel | Core I7-6820hq Firmware | All versions |
| Intel | Core I7-6822eq Firmware | All versions |
| Intel | Core I7-6870hq Firmware | All versions |
| Intel | Core I7-6920hq Firmware | All versions |
| Intel | Core I7-6970hq Firmware | All versions |
| Intel | Core I7-8550u Firmware | All versions |
| Intel | Core I7-8559u Firmware | All versions |
| Intel | Core I7-8650u Firmware | All versions |
| Intel | Core I7-8700b Firmware | All versions |
| Intel | Core I7-8700k Firmware | All versions |
| Intel | Core I7-8705g Firmware | All versions |
| Intel | Core I7-8706g Firmware | All versions |
| Intel | Core I7-8709g Firmware | All versions |
| Intel | Core I7-8750h Firmware | All versions |
| Intel | Core I7-8809g Firmware | All versions |
| Intel | Core I7-8850h Firmware | All versions |
| Intel | Core I3-6100 Firmware | All versions |
| Intel | Core I3-6100e Firmware | All versions |
| Intel | Core I3-6100h Firmware | All versions |
| Intel | Core I3-6100t Firmware | All versions |
| Intel | Core I3-6100te Firmware | All versions |
| Intel | Core I3-6100u Firmware | All versions |
| Intel | Core I3-6102e Firmware | All versions |
| Intel | Core I3-6110u Firmware | All versions |
| Intel | Core I3-6120 Firmware | All versions |
| Intel | Core I3-6120t Firmware | All versions |
| Intel | Core I3-6167u Firmware | All versions |
| Intel | Core I3-6300 Firmware | All versions |
| Intel | Core I3-6300t Firmware | All versions |
| Intel | Core I3-6320 Firmware | All versions |
| Intel | Core I3-6320t Firmware | All versions |
| Intel | Core I3-8000 Firmware | All versions |
| Intel | Core I3-8000t Firmware | All versions |
| Intel | Core I3-8020 Firmware | All versions |
| Intel | Core I3-8100 Firmware | All versions |
Showing 50 of 131 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29901?
How severe is CVE-2022-29901?
How do I fix CVE-2022-29901?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29896Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-29897On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an ad…9.1
- CVE-2022-29898On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an ad…9.1
- CVE-2022-29899Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-2990An incorrect handling of the supplementary groups in the Bui…7.1
- CVE-2022-29900Mis-trained branch predictions for return instructions may a…6.5
- CVE-2022-29903The Private Domains extension for MediaWiki through 1.37.2 (…4.3
- CVE-2022-29904The SemanticDrilldown extension for MediaWiki through 1.37.2…9.8
- CVE-2022-29905The FanBoxes extension for MediaWiki through 1.37.2 (before …4.3
- CVE-2022-29906The admin API module in the QuizGame extension for MediaWiki…9.8
- CVE-2022-29907The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb…6.1
- CVE-2022-29908The folioupdate service in Fabasoft Cloud Enterprise Client …7.8
Are you affected by CVE-2022-29901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
