CVE-2022-21125

medium
Published 2022-11-15 · Modified 2022-11-18
CVSS v3
VIR risk
5.5

Description

Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
almalinux almalinux9fixedkernel-rt-debug-core-5.14.0-162.6.1.rt21.168.el9_1.x86_64.rpm
redhat rhel9fixed
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed3.20220510.1
debian debianbullseyefixed3.20220510.1~deb11u1
debian debianforkyfixed3.20220510.1
debian debiansidfixed3.20220510.1
debian debiantrixiefixed3.20220510.1
rockylinux rocky9fixed
almalinux almalinux8fixedkernel-rt-debug-4.18.0-372.26.1.rt7.183.el8_6.x86_64.rpm

References

💬 Discuss CVE-2022-21125 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.