SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-29901

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data.

MEDIUM 6.5EPSS 4.83%

Does this matter?

Lower severity and a low EPSS score (4.83%). Track it; it rarely justifies an emergency change on its own.

Description

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
4.83% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-668
Affected
intel/core i7-6500u firmware · intel/core i7-6510u firmware · intel/core i7-6560u firmware · intel/core i7-6567u firmware · intel/core i7-6600u firmware · intel/core i7-6650u firmware · intel/core i7-6660u firmware · intel/core i7-6700 firmware · intel/core i7-6700hq firmware · intel/core i7-6700k firmware · intel/core i7-6700t firmware · intel/core i7-6700te firmware · intel/core i7-6770hq firmware · intel/core i7-6820eq firmware · intel/core i7-6820hk firmware · intel/core i7-6820hq firmware · intel/core i7-6822eq firmware · intel/core i7-6870hq firmware · intel/core i7-6920hq firmware · intel/core i7-6970hq firmware · +40 more
Source
secure@intel.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.