Vulnerability Description
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 11.0 |
| Fedoraproject | Fedora | 35 |
| Xen | Xen | - |
| Amd | Athlon X4 750 Firmware | - |
| Amd | Athlon X4 750 | - |
| Amd | Athlon X4 760K Firmware | - |
| Amd | Athlon X4 760K | - |
| Amd | Athlon X4 830 Firmware | - |
| Amd | Athlon X4 830 | - |
| Amd | Athlon X4 835 Firmware | - |
| Amd | Athlon X4 835 | - |
| Amd | Athlon X4 840 Firmware | - |
| Amd | Athlon X4 840 | - |
| Amd | Athlon X4 845 Firmware | - |
| Amd | Athlon X4 845 | - |
| Amd | Athlon X4 860K Firmware | - |
| Amd | Athlon X4 860K | - |
| Amd | Athlon X4 870K Firmware | - |
| Amd | Athlon X4 870K | - |
| Amd | Athlon X4 880K Firmware | - |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202402-07
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1037
- https://www.debian.org/security/2022/dsa-5207
- https://www.secpod.com/blog/retbleed-intel-and-amd-processor-information-disclos
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202402-07
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1037
- https://www.debian.org/security/2022/dsa-5207
- https://www.secpod.com/blog/retbleed-intel-and-amd-processor-information-disclos
FAQ
What is CVE-2022-29900?
CVE-2022-29900 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
How severe is CVE-2022-29900?
CVE-2022-29900 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29900?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Fedoraproject Fedora, Xen Xen, Amd Athlon X4 750 Firmware, Amd Athlon X4 750.