Wind River Support Network

HomeDefectsLIN1021-3944
Fixed

LIN1021-3944 : Security Advisory - linux - CVE-2022-29901

Created: Jul 12, 2022    Updated: Nov 9, 2022
Resolved Date: Aug 8, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.14
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CREATE(Triage):(User=admin) CVE-2022-29901 (https://nvd.nist.gov/vuln/detail/CVE-2022-29901)

CVEs


Live chat
Online