Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2022-29901

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

  • Published: Jul 12, 2022
  • Updated: Nov 8, 2023
  • CVE: CVE-2022-29901
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CVSS v2:

  • Severity: Low
  • Score: 1.9
  • AV:L/AC:M/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
fedoraproject / fedora 35 35.x
fedoraproject / fedora 36 36.x
vmware / esxi 7.0-beta 7.0-beta.x
vmware / esxi 7.0-update_1 7.0-update_1.x
vmware / esxi 7.0-update_1a 7.0-update_1a.x
vmware / esxi 7.0-update_1b 7.0-update_1b.x
vmware / esxi 7.0 7.0.x
vmware / esxi 7.0-update_2 7.0-update_2.x
vmware / esxi 7.0-update_2a 7.0-update_2a.x
vmware / esxi 7.0-update_2c 7.0-update_2c.x
vmware / esxi 7.0-update_2d 7.0-update_2d.x
vmware / esxi 7.0-update_1d 7.0-update_1d.x
vmware / esxi 7.0-update_1c 7.0-update_1c.x
vmware / esxi 7.0-update_3c 7.0-update_3c.x
vmware / esxi 7.0-update_3d 7.0-update_3d.x
vmware / esxi 7.0-update_3e 7.0-update_3e.x
vmware / esxi 7.0-update_2e 7.0-update_2e.x
debian / debian_linux 10.0 10.0.x
debian / debian_linux 11.0 11.0.x