MEDIUM · 5.5

CVE-2022-23824

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

Vulnerability Description

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
XenXen-
AmdA10-9600P-
AmdA10-9630P-
AmdA12-9700P-
AmdA12-9730P-
AmdA4-9120-
AmdA6-9210-
AmdA6-9220-
AmdA6-9220C-
AmdA9-9410-
AmdA9-9420-
AmdAthlon Gold 3150U-
AmdAthlon Silver 3050U-
AmdAthlon X4 750-
AmdAthlon X4 760K-
AmdAthlon X4 830-
AmdAthlon X4 835-
AmdAthlon X4 840-
AmdAthlon X4 845-
AmdAthlon X4 860K-

References

FAQ

What is CVE-2022-23824?

CVE-2022-23824 is a vulnerability with a CVSS score of 5.5 (MEDIUM). IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

How severe is CVE-2022-23824?

CVE-2022-23824 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23824?

Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen, Amd A10-9600P, Amd A10-9630P, Amd A12-9700P, Amd A12-9730P.