跳转到帖子

Oracle Linux: CVE-2022-40982: ELSA-2023-12782: Unbreakable Enterprise kernel security update (IMPORTANT) (Multiple Advisories)

recommended_posts

发布于
  • Members

Oracle Linux: CVE-2022-40982: ELSA-2023-12782:Unbreakable Enterprise kernel security update (IMPORTANT) (Multiple Advisories)

Severity
5
CVSS
(AV:L/AC:L/Au:S/C:C/I:N/A:N)
Published
08/08/2023
Created
08/16/2023
Added
08/15/2023
Modified
01/23/2025

Description

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. A Gather Data Sampling (GDS) transient execution side-channel vulnerability was found affecting certain Intel processors. This issue may allow a local attacker using gather instruction (load from memory) to infer stale data from previously used vector registers on the same physical core.

Solution(s)

  • oracle-linux-upgrade-kernel
  • oracle-linux-upgrade-kernel-uek

References

  • https://attackerkb.com/topics/cve-2022-40982
  • CVE - 2022-40982
  • ELSA-2023-12782
  • ELSA-2023-12722
  • ELSA-2023-12788
  • ELSA-2023-12723
  • ELSA-2023-7077
  • ELSA-2023-12786
  • ELSA-2023-7423
  • ELSA-2023-12785
  • ELSA-2023-6583
  • ELSA-2023-12724
View more
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…