UBUNTU-CVE-2022-21127
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
02 / AFFECTED SOFTWARE
Affected packages
20 explicit affected versions
11 explicit affected versions
1 explicit affected versions
22 explicit affected versions
21 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2022-21127
- https://ubuntu.com/security/notices/USN-5486-1
- https://ubuntu.com/security/notices/USN-5535-1
- https://www.cve.org/CVERecord?id=CVE-2022-21127
- https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/processor-mmio-stale-data-vulnerabilities.html#SRBDS-Update
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html
- https://xenbits.xen.org/xsa/advisory-404.html