Lucene search

K
f5F5F5:K83713003
HistoryAug 02, 2022 - 12:00 a.m.

K83713003 : RetBleed CPU vulnerability CVE-2022-29901

2022-08-0200:00:00
my.f5.com
82

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.2%

Security Advisory Description

There are two RetBleed vulnerabilities. This article applies to CVE-2022-29901. For information about CVE-2022-29900 refer to the following article:

K57185580: RetBleed CPU vulnerability CVE-2022-29900

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions. (CVE-2022-29901)

Impact

A local authenticated attacker can exploit the Intel vulnerability to allow information disclosure. Only the VELOS BX110 platform is vulnerable.

For more information, refer to K86001294: F5OS hardware/software support matrix.