6.5
CVSSv3

CVE-2022-40982

Published: 11/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors. This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core. (CVE-2022-40982) A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. (CVE-2023-20588) A buffer overrun vulnerability was found in the netback driver in Xen due to an unusual split packet. This flaw allows an unprivileged guest to cause a denial of service (DoS) of the host by sending network packets to the backend, causing the backend to crash. (CVE-2023-34319) A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system. (CVE-2023-4004) A use-after-free flaw was found in net/sched/cls_fw.c in classifiers (cls_fw, cls_u32, and cls_route) in the Linux Kernel. This flaw allows a local malicious user to perform a local privilege escalation due to incorrect handling of the existing filter, leading to a kernel information leak issue. (CVE-2023-4128) netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID (CVE-2023-4147)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 7.0

xen xen -

redhat enterprise linux 6.0

redhat enterprise linux 8.0

redhat enterprise linux 9.0

intel microcode

intel xeon e-2314 firmware -

intel xeon e-2324g firmware -

intel xeon e-2334 firmware -

intel xeon e-2374g firmware -

intel xeon e-2336 firmware -

intel xeon e-2356g firmware -

intel xeon e-2386g firmware -

intel xeon e-2378 firmware -

intel xeon e-2378g firmware -

intel xeon e-2388g firmware -

intel xeon w-1350 firmware -

intel xeon w-1350p firmware -

intel xeon w-1370 firmware -

intel xeon w-1370p firmware -

intel xeon w-1390t firmware -

intel xeon w-1390 firmware -

intel xeon w-1390p firmware -

intel core i9-11900t firmware -

intel core i9-11900f firmware -

intel core i9-11900 firmware -

intel core i9-11900kf firmware -

intel core i9-11900k firmware -

intel core i7-11700t firmware -

intel core i7-11700f firmware -

intel core i7-11700 firmware -

intel core i7-11700kf firmware -

intel core i7-11700k firmware -

intel core i5-11400t firmware -

intel core i5-11400f firmware -

intel core i5-11400 firmware -

intel core i5-11500t firmware -

intel core i5-11500 firmware -

intel core i5-11600t firmware -

intel core i5-11600 firmware -

intel core i5-11600kf firmware -

intel core i5-11600k firmware -

intel celeron g5900t firmware -

intel celeron g5920 firmware -

intel celeron g5900 firmware -

intel celeron g5925 firmware -

intel celeron g5905t firmware -

intel celeron g5905 firmware -

intel pentium gold g6500t firmware -

intel pentium gold g6600 firmware -

intel pentium gold g6400t firmware -

intel pentium gold g6400 firmware -

intel pentium gold g6500 firmware -

intel pentium gold g6605 firmware -

intel pentium gold g6505t firmware -

intel pentium gold g6505 firmware -

intel pentium gold g6405 firmware -

intel pentium gold g6405t firmware -

intel core i3-10100t firmware -

intel core i3-10100 firmware -

intel core i3-10300t firmware -

intel core i3-10300 firmware -

intel core i3-10320 firmware -

intel core i3-10100f firmware -

intel core i3-10105 firmware -

intel core i3-10305 firmware -

intel core i3-10305t firmware -

intel core i3-10105t firmware -

intel core i3-10325 firmware -

intel core i3-10105f firmware -

intel core i5-10600 firmware -

intel core i5-10400 firmware -

intel core i5-10400f firmware -

intel core i5-10500 firmware -

intel core i5-10400t firmware -

intel core i5-10500t firmware -

intel core i5-10600t firmware -

intel core i5-10600kf firmware -

intel core i5-10600k firmware -

intel core i5-10505 firmware -

intel core i7-10700 firmware -

intel core i7-10700t firmware -

intel core i7-10700k firmware -

intel core i7-10700kf firmware -

intel core i7-10700f firmware -

intel core i9-10900k firmware -

intel core i9-10900kf firmware -

intel core i9-10900f firmware -

intel core i9-10900 firmware -

intel core i9-10900t firmware -

intel core i9-10850k firmware -

intel pentium gold 6405u firmware -

intel core i5-10300h firmware -

intel core i5-10400h firmware -

intel core i5-10200h firmware -

intel core i5-10500h firmware -

intel core i7-10750h firmware -

intel core i7-10875h firmware -

intel core i7-10850h firmware -

intel core i7-10870h firmware -

intel core i9-10980hk firmware -

intel core i9-10885h firmware -

intel xeon w-10885m firmware -

intel xeon w-10855m firmware -

intel xeon w-1250 firmware -

intel xeon w-1290t firmware -

intel xeon w-1250p firmware -

intel xeon w-1270 firmware -

intel xeon w-1270p firmware -

intel xeon w-1290 firmware -

intel xeon w-1290p firmware -

intel core i9-9900t firmware -

intel core i9-9900 firmware -

intel core i9-9900kf firmware -

intel core i9-9900k firmware -

intel core i9-9900ks firmware -

intel core i7-9700t firmware -

intel core i7-9700f firmware -

intel core i7-9700 firmware -

intel core i7-9700kf firmware -

intel core i7-9700k firmware -

intel core i5-9400t firmware -

intel core i5-9400f firmware -

intel core i5-9400 firmware -

intel core i5-9500t firmware -

intel core i5-9500f firmware -

intel core i5-9500 firmware -

intel core i5-9600t firmware -

intel core i5-9600 firmware -

intel core i5-9600kf firmware -

intel core i5-9600k firmware -

intel core i3-9100t firmware -

intel core i3-9100f firmware -

intel core i3-9100 firmware -

intel core i3-9300t firmware -

intel core i3-9300 firmware -

intel core i3-9320 firmware -

intel core i3-9350k firmware -

intel core i3-9350kf firmware -

intel core i7-8086k firmware -

intel core i3-8100f firmware -

intel celeron g4900t firmware -

intel celeron g4900 firmware -

intel celeron g4920 firmware -

intel pentium gold g5400t firmware -

intel pentium gold g5500t firmware -

intel pentium gold g5400 firmware -

intel pentium gold g5500 firmware -

intel pentium gold g5600 firmware -

intel core i3-8100t firmware -

intel core i3-8300t firmware -

intel core i3-8100 firmware -

intel core i3-8300 firmware -

intel core i3-8350k firmware -

intel core i5-8400t firmware -

intel core i5-8500t firmware -

intel core i5-8600t firmware -

intel core i5-8400 firmware -

intel core i5-8500 firmware -

intel core i5-8600 firmware -

intel core i5-8600k firmware -

intel core i7-8700t firmware -

intel core i7-8700 firmware -

intel core i7-8700k firmware -

intel xeon e-2278gel firmware -

intel xeon e-2278ge firmware -

intel xeon e-2226ge firmware -

intel xeon e-2288g firmware -

intel xeon e-2286g firmware -

intel xeon e-2278g firmware -

intel xeon e-2276g firmware -

intel xeon e-2274g firmware -

intel xeon e-2246g firmware -

intel xeon e-2244g firmware -

intel xeon e-2236 firmware -

intel xeon e-2234 firmware -

intel xeon e-2226g firmware -

intel xeon e-2224g firmware -

intel xeon e-2224 firmware -

intel xeon e-2186g firmware -

intel xeon e-2176g firmware -

intel xeon e-2174g firmware -

intel xeon e-2146g firmware -

intel xeon e-2144g firmware -

intel xeon e-2136 firmware -

intel xeon e-2134 firmware -

intel xeon e-2126g firmware -

intel xeon e-2124g firmware -

intel xeon e-2124 firmware -

intel xeon e-2104g firmware -

intel core i9-8950hk firmware -

intel core i7-8557u firmware -

intel core i7-8569u firmware -

intel core i7-8700b firmware -

intel core i7-8750h firmware -

intel core i7-8850h firmware -

intel core i5-8257u firmware -

intel core i5-8260u firmware -

intel core i5-8279u firmware -

intel core i5-8300h firmware -

intel core i5-8400h firmware -

intel core i5-8400b firmware -

intel core i5-8500b firmware -

intel core i3-8100h firmware -

intel core i3-8100b firmware -

intel xeon e3-1501l v6 firmware -

intel xeon e3-1501m v6 firmware -

intel xeon e3-1505m v6 firmware -

intel xeon e3-1535m v6 firmware -

intel xeon e3-1505l v6 firmware -

intel xeon e3-1275 v6 firmware -

intel xeon e3-1225 v6 firmware -

intel xeon e3-1280 v6 firmware -

intel xeon e3-1230 v6 firmware -

intel xeon e3-1270 v6 firmware -

intel xeon e3-1245 v6 firmware -

intel xeon e3-1220 v6 firmware -

intel xeon e3-1240 v6 firmware -

intel xeon e3-1285 v6 firmware -

intel core i5-7640x firmware -

intel core i7-7740x firmware -

intel core i5-8305g firmware -

intel core i7-8809g firmware -

intel core i7-8709g firmware -

intel core i7-8705g firmware -

intel core i7-8706g firmware -

intel core i3-7102e firmware -

intel core i3-7100e firmware -

intel core i5-7442eq firmware -

intel core i5-7440eq firmware -

intel core i7-7820eq firmware -

intel core i7-7700t firmware -

intel core i7-7700k firmware -

intel core i7-7700 firmware -

intel core i5-7600t firmware -

intel core i5-7600k firmware -

intel core i5-7600 firmware -

intel core i5-7500t firmware -

intel core i5-7500 firmware -

intel core i5-7400t firmware -

intel core i5-7400 firmware -

intel core i3-7350k firmware -

intel core i3-7340 firmware -

intel core i3-7320t firmware -

intel core i3-7320 firmware -

intel core i3-7310t firmware -

intel core i3-7300t firmware -

intel core i3-7300 firmware -

intel core i3-7120t firmware -

intel core i3-7120 firmware -

intel core i3-7101te firmware -

intel core i3-7101e firmware -

intel core i3-7100t firmware -

intel core i3-7100 firmware -

intel core i3-10110y firmware -

intel core i3-10100y firmware -

intel core i5-10210y firmware -

intel core i5-10310y firmware -

intel core i7-10510y firmware -

intel core i7-10810u firmware -

intel core i7-10710u firmware -

intel core i7-10610u firmware -

intel core i7-10510u firmware -

intel core i5-10310u firmware -

intel core i5-10210u firmware -

intel core i3-10110u firmware -

intel pentium 6405u firmware -

intel celeron 5305u firmware -

intel celeron 5205u firmware -

intel core i3-8145u firmware -

intel core i5-8265u firmware -

intel core i5-8365u firmware -

intel core i7-8565u firmware -

intel core i7-8665u firmware -

intel core i3-8130u firmware -

intel core i3-7020u firmware -

intel core i5-8350u firmware -

intel core i5-8250u firmware -

intel core i7-8650u firmware -

intel core i7-8550u firmware -

intel core i3-8109u firmware -

intel core i5-8269u firmware -

intel core i5-8259u firmware -

intel core i7-8559u firmware -

intel core i3-7167u firmware -

intel core i5-7360u firmware -

intel core i5-7287u firmware -

intel core i5-7267u firmware -

intel core i5-7260u firmware -

intel core i7-7660u firmware -

intel core i7-7567u firmware -

intel core i7-7560u firmware -

intel core i3-7100u firmware -

intel core i5-7300u firmware -

intel core i7-7600u firmware -

intel core m3-8100y firmware -

intel core i5-8200y firmware -

intel core i5-8210y firmware -

intel core i5-8310y firmware -

intel core i7-8500y firmware -

intel xeon w-11155mle firmware -

intel xeon w-11555mle firmware -

intel xeon w-11865mle firmware -

intel xeon w-11155mre firmware -

intel xeon w-11555mre firmware -

intel xeon w-11865mre firmware -

intel core i3-1115g4e firmware -

intel core i3-1115gre firmware -

intel core i3-11100he firmware -

intel core i5-1145gre firmware -

intel core i5-1145g7e firmware -

intel core i5-11500he firmware -

intel core i7-1185g7e firmware -

intel core i7-1185gre firmware -

intel core i7-11850he firmware -

intel core i3-1115g4 firmware -

intel core i3-1110g4 firmware -

intel core i3-1120g4 firmware -

intel core i3-1125g4 firmware -

intel core i5-1130g7 firmware -

intel core i5-1135g7 firmware -

intel core i5-1145g7 firmware -

intel core i5-1140g7 firmware -

intel core i5-11300h firmware -

intel core i5-11260h firmware -

intel core i5-11400h firmware -

intel core i5-11500h firmware -

intel core i5-1155g7 firmware -

intel core i5-11320h firmware -

intel core i7-1185g7 firmware -

intel core i7-1160g7 firmware -

intel core i7-1165g7 firmware -

intel core i7-11375h firmware -

intel core i7-11370h firmware -

intel core i7-1180g7 firmware -

intel core i7-11850h firmware -

intel core i7-11800h firmware -

intel core i7-1195g7 firmware -

intel core i7-11390h firmware -

intel core i7-11600h firmware -

intel core i9-11900h firmware -

intel core i9-11980hk firmware -

intel core i9-11950h firmware -

intel core i7-1060g7 firmware -

intel core i5-1030g7 firmware -

intel core i5-1030g4 firmware -

intel core i3-1000g4 firmware -

intel core i3-1000g1 firmware -

intel core i7-1068g7 firmware -

intel core i7-1065g7 firmware -

intel core i5-1035g7 firmware -

intel core i5-1035g4 firmware -

intel core i5-1035g1 firmware -

intel core i3-1005g1 firmware -

intel xeon d-2796te firmware -

intel xeon d-2775te firmware -

intel xeon d-2752ter firmware -

intel xeon d-2733nt firmware -

intel xeon d-2712t firmware -

intel xeon d-1746ter firmware -

intel xeon d-1735tr firmware -

intel xeon d-1732te firmware -

intel xeon d-1715ter firmware -

intel xeon d-1712tr firmware -

intel xeon silver 4310t firmware -

intel xeon silver 4310 firmware -

intel xeon silver 4314 firmware -

intel xeon silver 4316 firmware -

intel xeon gold 5315y firmware -

intel xeon gold 5317 firmware -

intel xeon gold 5320t firmware -

intel xeon gold 5318y firmware -

intel xeon gold 6326 firmware -

intel xeon gold 6336y firmware -

intel xeon gold 6338t firmware -

intel xeon gold 6330 firmware -

intel xeon platinum 8380hl firmware -

intel xeon platinum 8380h firmware -

intel xeon platinum 8376hl firmware -

intel xeon platinum 8376h firmware -

intel xeon platinum 8360hl firmware -

intel xeon platinum 8360h firmware -

intel xeon platinum 8356h firmware -

intel xeon platinum 8354h firmware -

intel xeon platinum 8353h firmware -

intel xeon gold 6348h firmware -

intel xeon gold 6330h firmware -

intel xeon gold 6328hl firmware -

intel xeon gold 6328h firmware -

intel xeon gold 5320h firmware -

intel xeon gold 5318h firmware -

intel core i9-10900x firmware -

intel core i9-10920x firmware -

intel core i9-10940x firmware -

intel core i9-10980xe firmware -

intel xeon w-2223 firmware -

intel xeon w-2225 firmware -

intel xeon w-2235 firmware -

intel xeon w-2245 firmware -

intel xeon w-2255 firmware -

intel xeon w-2265 firmware -

intel xeon w-2275 firmware -

intel xeon w-2295 firmware -

intel xeon w-3223 firmware -

intel xeon w-3225 firmware -

intel xeon w-3235 firmware -

intel xeon w-3245 firmware -

intel xeon w-3245m firmware -

intel xeon w-3265 firmware -

intel xeon w-3265m firmware -

intel xeon w-3275 firmware -

intel xeon w-3275m firmware -

intel xeon silver 4216 firmware -

intel xeon silver 4215r firmware -

intel xeon silver 4215 firmware -

intel xeon silver 4214y firmware -

intel xeon silver 4214r firmware -

intel xeon silver 4214 firmware -

intel xeon silver 4210t firmware -

intel xeon silver 4210r firmware -

intel xeon silver 4210 firmware -

intel xeon silver 4209t firmware -

intel xeon silver 4208 firmware -

intel xeon platinum 9282 firmware -

intel xeon platinum 9242 firmware -

intel xeon platinum 9222 firmware -

intel xeon platinum 9221 firmware -

intel xeon platinum 8280l firmware -

intel xeon platinum 8280 firmware -

intel xeon platinum 8276l firmware -

intel xeon platinum 8276 firmware -

intel xeon platinum 8270 firmware -

intel xeon platinum 8268 firmware -

intel xeon platinum 8260y firmware -

intel xeon platinum 8260l firmware -

intel xeon platinum 8260 firmware -

intel xeon platinum 8256 firmware -

intel xeon platinum 8253 firmware -

intel xeon gold 6262v firmware -

intel xeon gold 6258r firmware -

intel xeon gold 6256 firmware -

intel xeon gold 6254 firmware -

intel xeon gold 6252n firmware -

intel xeon gold 6252 firmware -

intel xeon gold 6250l firmware -

intel xeon gold 6250 firmware -

intel xeon gold 6248r firmware -

intel xeon gold 6248 firmware -

intel xeon gold 6246r firmware -

intel xeon gold 6246 firmware -

intel xeon gold 6244 firmware -

intel xeon gold 6242r firmware -

intel xeon gold 6242 firmware -

intel xeon gold 6240y firmware -

intel xeon gold 6240r firmware -

intel xeon gold 6240l firmware -

intel xeon gold 6240 firmware -

intel xeon gold 6238t firmware -

intel xeon gold 6238r firmware -

intel xeon gold 6238l firmware -

intel xeon gold 6238 firmware -

intel xeon gold 6234 firmware -

intel xeon gold 6230t firmware -

intel xeon gold 6230r firmware -

intel xeon gold 6230n firmware -

intel xeon gold 6230 firmware -

intel xeon gold 6226r firmware -

intel xeon gold 6226 firmware -

intel xeon gold 6222v firmware -

intel xeon gold 6212u firmware -

intel xeon gold 6210u firmware -

intel xeon gold 6209u firmware -

intel xeon gold 6208u firmware -

intel xeon gold 5222 firmware -

intel xeon gold 5220t firmware -

intel xeon gold 5220s firmware -

intel xeon gold 5220r firmware -

intel xeon gold 5220 firmware -

intel xeon gold 5218t firmware -

intel xeon gold 5218r firmware -

intel xeon gold 5218n firmware -

intel xeon gold 5218b firmware -

intel xeon gold 5218 firmware -

intel xeon gold 5217 firmware -

intel xeon gold 5215l firmware -

intel xeon gold 5215 firmware -

intel xeon bronze 3206r firmware -

intel xeon bronze 3204 firmware -

intel core i7-9800x firmware -

intel core i7-7800x firmware -

intel core i7-7820x firmware -

intel core i9-9820x firmware -

intel core i9-9900x firmware -

intel core i9-9920x firmware -

intel core i9-9940x firmware -

intel core i9-9960x firmware -

intel core i9-9980xe firmware -

intel core i9-9990xe firmware -

intel core i9-7900x firmware -

intel core i9-7920x firmware -

intel core i9-7940x firmware -

intel core i9-7960x firmware -

intel core i9-7980xe firmware -

intel xeon d-2187nt firmware -

intel xeon d-2183it firmware -

intel xeon d-2177nt firmware -

intel xeon d-2173it firmware -

intel xeon d-2166nt firmware -

intel xeon d-2163it firmware -

intel xeon d-2161i firmware -

intel xeon d-2146nt firmware -

intel xeon d-2145nt firmware -

intel xeon d-2143it firmware -

intel xeon d-2142it firmware -

intel xeon d-2141i firmware -

intel xeon d-2123it firmware -

intel xeon w-2195 firmware -

intel xeon w-2175 firmware -

intel xeon w-2155 firmware -

intel xeon w-2145 firmware -

intel xeon w-2135 firmware -

intel xeon w-2133 firmware -

intel xeon w-2125 firmware -

intel xeon w-2123 firmware -

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

netapp all flash fabric-attached storage a400 -

netapp all flash fabric-attached storage 8300 -

netapp all flash fabric-attached storage 8700 -

netapp all flash fabric-attached storage 2820 -

netapp all flash fabric-attached storage a800 -

netapp all flash fabric-attached storage c800 -

netapp all flash fabric-attached storage a900 -

netapp all flash fabric-attached storage 9500 -

netapp all flash fabric-attached storage c400 -

netapp all flash fabric-attached storage c250

netapp all flash fabric-attached storage 500f

netapp all flash fabric-attached storage a250

Vendor Advisories

Debian Bug report logs - #1043305 intel-microcode: CVE-2022-40982 CVE-2022-41804 CVE-2023-23908 Package: src:intel-microcode; Maintainer for src:intel-microcode is Henrique de Moraes Holschuh <hmh@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 8 Aug 2023 19:27:04 UTC Severity: grave Ta ...
This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities CVE-2022-40982 Daniel Moghimi discovered Gather Data Sampling (GDS), a hardware vulnerability which allows unprivileged speculative access to data which was previously stored in vector registers For details p ...
CVE-2022-40982 Daniel Moghimi discovered Gather Data Sampling (GDS), a hardware vulnerability for Intel CPUs which allows unprivileged speculative access to data which was previously stored in vector registers This mitigation requires updated CPU microcode provided in the intel-microcode package For details please refer to ...
概要 Important: kernel security, bug fix, and enhancement update タイプ/重大度 Security Advisory: Important Red Hat Insights パッチ分析 このアドバイザリーの影響を受けるシステムを特定し、修正します。 影響を受けるシステムの表示 トピック An update for kernel is now available ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 88 Extended Update SupportRed Hat P ...
Synopsis Low: Logging Subsystem 5710 - Red Hat OpenShift security update Type/Severity Security Advisory: Low Topic Low: Logging Subsystem 5710 - Red Hat OpenShift security updateRed Hat Product Security has rated this update as having a security impact of low A Common Vulnerability Scoring System (CVSS) base score, which gives a detaile ...
Synopsis Important: kernel-rt security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 92 Extended Update SupportRed Hat Product Security has ...
概要 Important: OpenShift Container Platform 411 low-latency extras update タイプ/重大度 Security Advisory: Important トピック An update for cnf-tests-container, dpdk-base-container and performance-addon-operator-must-gather-rhel8-container is now available for Red Hat OpenShift Container Platform 411 Secondary scheduler builds ...
Synopsis Important: kernel-rt security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as havin ...
概要 Important: kernel security update タイプ/重大度 Security Advisory: Important Red Hat Insights パッチ分析 このアドバイザリーの影響を受けるシステムを特定し、修正します。 影響を受けるシステムの表示 トピック An update for kernel is now available for Red Hat Enterprise Lin ...
Synopsis Important: OpenShift Container Platform 4142 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4142 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift C ...
Synopsis Low: Logging Subsystem 581- Red Hat OpenShift security update Type/Severity Security Advisory: Low Topic An update is now available for RHOL-58-RHEL-9Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, i ...
Synopsis Important: OpenShift Container Platform 41247 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41247 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container P ...
A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core (CVE-2022-40982) A division-by-zero error on some AMD process ...
A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core (CVE-2022-40982) ...
Description<!---->A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical coreA Gather Data Sampling (GDS) transient execu ...

Github Repositories

cve-import A tool to import CVE records to a database from json files CVE JSON files are fetched from CVEProject/cvelistV5 Setup Clone the repo and install packages with yarn Copy envsample to env, and enter your Postgres credentials Run yarn migrate to apply the prisma schema to you database Clone cvelistV5 into an adjacent folder of cve-import (/cvelistV5 relative t

A tiny tool for embedding CoSWID tags in EFI binaries

python-uswid Introduction A Software Bill of Materials (SBoM) is a manifest of what components are included inside your software It helps vendors and consumers keep track of software components for better software supply chain security When building or creating a SBoM there are lots of formats to choose from: SWID coSWID CycloneDX SPDX goSWID Using the uSWID tool allows you

Recent Articles

Microsoft, Intel lead this month's security fix emissions
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Downfall processor leaks, Teams holes, VPN clients at risk, and more

Patch Tuesday Microsoft's August patch party seems almost boring compared to the other security fires it's been putting out lately. Of the almost 90 flaws addressed today, two are listed as being under active exploitation. Redmond deemed six of the August CVE-tagged bugs as critical, though we note there are 26 vulnerabilities that can lead to remote code execution (RCE). One of the two that miscreants have already found and exploited doesn't yet have a patch. The advisory for that flaw, ADV2300...

Downfall fallout: Intel knew AVX chips were insecure and did nothing, lawsuit claims
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Billions of data-leaking processors sold despite warnings and patch just made them slower, punters complain

Intel has been sued by a handful of PC buyers who claim the x86 goliath failed to act when informed five years ago about faulty chip instructions that allowed the recent Downfall vulnerability, and during that period sold billions of insecure chips. The lawsuit [PDF], filed on behalf of five plaintiffs in a US federal court in San Jose, California, claims Intel knew about the susceptibility of its AVX instruction set to side-channel attacks since 2018, but didn't fix the defect until the disclos...