Wind River Support Network

HomeDefectsLINCD-9780
Fixed

LINCD-9780 : Security Advisory - linux - CVE-2022-29901

Created: Jul 12, 2022    Updated: Sep 14, 2022
Resolved Date: Aug 22, 2022
Found In Version: 10.20.6.0
Fix Version: 10.22.36.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Kernel

Description

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CREATE(Triage):(User=admin) CVE-2022-29901 (https://nvd.nist.gov/vuln/detail/CVE-2022-29901)

CVEs


Live chat
Online