VDB
BDU%3A2022-04387
BDU%3A2022-04387
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Уязвимость микропрограммного обеспечения процессоров Intel и AMD, позволяющая нарушителю раскрыть защищаемую информацию из памяти ядра или осуществить атаку на хост-систему из виртуальных машин
Risk Scores
CVSS 2.0
4.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., ООО «РусБИТех-Астра», Novell Inc., Intel Corp., Сообщество свободного программного обеспечения, Fedora Project, ООО «Ред Софт», Advanced Micro Devices Inc., АО "НППКТ" | Red Hat Enterprise Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, 7th Generation Intel Core, 8th Generation Intel Core, 6th Generation Intel Core, SUSE Linux Enterprise High Availability, SUSE Linux Enterprise Live Patching, SUSE Linux Enterprise Software Development Kit, SUSE OpenStack Cloud, Debian GNU/Linux, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Workstation Extension, Suse Linux Enterprise Desktop, OpenSUSE Leap, Fedora, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Manager Proxy, SUSE Manager Server, 1st Gen AMD EPYC, 2nd Gen AMD EPYC, SUSE Manager Retail Branch Server, SUSE Linux Enterprise Module for Public Cloud, AMD Ryzen 2000 series Desktop, AMD Ryzen 3000 Series Desktop, AMD Ryzen 4000 Series Desktop processors with Radeon graphics, 2nd Gen AMD Ryzen Threadripper, 3rd Gen AMD Ryzen Threadripper, AMD Ryzen Threadripper PRO processors, AMD Athlon 3000 Series Mobile processors with Radeon graphics, AMD Ryzen 2000 Series Mobile processor, 2nd Gen AMD Ryzen Mobile processor with Radeon graphics, AMD Ryzen 5000 Series Mobile processor with Radeon graphics, AMD Athlon Mobile processor with Radeon graphics, AMD Athlon X4 processor, 7th Generation AMD A-Series APUs, SUSE Enterprise Storage, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Linux |
Timeline
- Jul 15, 2022 CVE Published
- Sep 30, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- http://www.openwall.com/lists/oss-security/2022/07/12/2 url
- http://www.openwall.com/lists/oss-security/2022/07/12/4 url
- http://www.openwall.com/lists/oss-security/2022/07/12/5 url
- http://www.openwall.com/lists/oss-security/2022/07/13/1 url
- https://access.redhat.com/security/cve/CVE-2022-29900 url
- https://comsec.ethz.ch/research/microarch/retbleed/ url
- https://comsec.ethz.ch/retbleed url
- https://comsec.ethz.ch/wp-content/files/retbleed_sec22.pdf url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29900 url
- https://github.com/comsec-group/retbleed url
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.266 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.133 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.57 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.14 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D4RW5FCIYFNCQOEFJEUIRW3DGYW7CWBG/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M27MB3QFNIJV4EQQSXWARHP3OGX6CR6K/ url
- https://security-tracker.debian.org/tracker/CVE-2022-29900 url
- https://ubuntu.com/security/notices/USN-5564-1 url
- https://ubuntu.com/security/notices/USN-5565-1 url
- https://ubuntu.com/security/notices/USN-5566-1 url
…and 23 more