CVE-2022-29901: Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed)
Published Jul 1, 2022
·
Updated
A flaw was found in hw. Non-transparent sharing of branch predictor targets between contexts in some Intel(R) processors may potentially allow an authorized user to enable information disclosure via local access.
Other sources
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Non-transparent sharing of branch predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Recommended actions to resolve this vulnerability, in priority order.
Upgrade
Upgrade redhat/kernel-rt to a version that resolves this vulnerability.
Fixed in 0:3.10.0-1160.80.1.rt56.1225.el7
Upgrade
Upgrade redhat/kernel to a version that resolves this vulnerability.
Fixed in 0:3.10.0-1160.80.1.el7
Upgrade
Upgrade redhat/kernel-rt to a version that resolves this vulnerability.
Fixed in 0:4.18.0-372.32.1.rt7.189.el8_6
Upgrade
Upgrade redhat/kernel to a version that resolves this vulnerability.
Fixed in 0:4.18.0-372.32.1.el8_6
Upgrade
Upgrade redhat/kernel to a version that resolves this vulnerability.
Fixed in 0:5.14.0-162.6.1.el9_1
Upgrade
Upgrade redhat/kernel-rt to a version that resolves this vulnerability.
Fixed in 0:5.14.0-162.6.1.rt21.168.el9_1
Upgrade
Upgrade redhat/kernel to a version that resolves this vulnerability.
Fixed in 0:5.14.0-70.36.1.el9_0
Upgrade
Upgrade redhat/kernel-rt to a version that resolves this vulnerability.
Fixed in 0:5.14.0-70.36.1.rt21.108.el9_0
Upgrade
Upgrade debian/linux to a version that resolves this vulnerability.
Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1
Configuration
Enable IBRS on affected Skylake generation processors to mitigate Retbleed/speculative return-instruction hijacking and related speculative execution data leakage risks.
Enable IBRS on affected Intel microprocessor generations 6 to 8 to mitigate a Spectre variant that can bypass kernel retpoline mitigation and leak arbitrary data.
Mitigate the information disclosure risk from non-transparent sharing of branch predictor targets between contexts by limiting local access (authorized user access) per your environment’s local-user exposure controls.
Event History
Jul 1, 2022
Data Sourced
via Red Hat·02:46 PM
DescriptionSeverityAffected Software
Jul 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 22, 2026
Data Sourced
via Launchpad·11:09 AM
Description
Aug 27, 2026
Data Sourced
via Ubuntu·12:42 PM
RemedyDescriptionSeverityAffected Software
Sep 4, 2026
Data Sourced
via Debian·12:58 PM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.
CVE-2022-29901 has been classified with a high severity level due to the potential for information disclosure in affected Intel processors.
2
How do I fix CVE-2022-29901?
To mitigate CVE-2022-29901, users should update their systems to the latest provided kernel versions as specified in the vulnerability advisory.
3
What Intel processors are affected by CVE-2022-29901?
CVE-2022-29901 affects certain Intel processors from generations 6 to 8, including various Core i7, i5, and i3 models.
4
Can CVE-2022-29901 be exploited locally?
Yes, CVE-2022-29901 can be exploited by an authorized user with local access, potentially leading to information disclosure.
5
What should I do if my system is vulnerable to CVE-2022-29901?
If your system is vulnerable to CVE-2022-29901, immediately apply the necessary software updates and security patches provided by your operating system vendor.
SecAlerts Pty Ltd. 132 Wickham Terrace Fortitude Valley, QLD 4006, Australia info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.