← Vulnerability feed

Vulnerability record · CVE-2022-40982 · published 11 August 2023

CVE-2022-40982: Redhat enterprise linux observable discrepancy vulnerability

Redhat · Enterprise Linux

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

6.5 CVSS 3.1 Medium EPSS 3.0% · top 13.0% CWE-1342 · CWE-1342CWE-203 · Observable discrepancy
6.5CVSS 3.1 base score
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
29References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html ExploitMitigationVendor Advisory
https://access.redhat.com/solutions/7027704 Third Party Advisory
https://aws.amazon.com/security/security-bulletins/AWS-2023-007/ Third Party Advisory
https://downfall.page ExploitTechnical DescriptionThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00013.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKREYYTWUY7ZDNIB2N6H5BUJ3
https://lists.fedoraproject.org/archives/list/[email protected]/message/OL7WI2TJCWSZIQP2RIOLWHOKL
https://lists.fedoraproject.org/archives/list/[email protected]/message/T7WO5JM74YJSYAE5RBV4DC6A4
https://security.netapp.com/advisory/ntap-20230811-0001/ Third Party Advisory
https://www.debian.org/security/2023/dsa-5474 Mailing ListThird Party Advisory
https://www.debian.org/security/2023/dsa-5475 Mailing ListThird Party Advisory
https://xenbits.xen.org/xsa/advisory-435.html MitigationThird Party Advisory
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html ExploitMitigationVendor Advisory
http://xenbits.xen.org/xsa/advisory-435.html
https://access.redhat.com/solutions/7027704 Third Party Advisory
https://aws.amazon.com/security/security-bulletins/AWS-2023-007/ Third Party Advisory
https://downfall.page ExploitTechnical DescriptionThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00013.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKREYYTWUY7ZDNIB2N6H5BUJ3
https://lists.fedoraproject.org/archives/list/[email protected]/message/OL7WI2TJCWSZIQP2RIOLWHOKL
https://lists.fedoraproject.org/archives/list/[email protected]/message/T7WO5JM74YJSYAE5RBV4DC6A4
https://security.netapp.com/advisory/ntap-20230811-0001/ Third Party Advisory
https://www.debian.org/security/2023/dsa-5474 Mailing ListThird Party Advisory
https://www.debian.org/security/2023/dsa-5475 Mailing ListThird Party Advisory
https://xenbits.xen.org/xsa/advisory-435.html MitigationThird Party Advisory

Track CVE-2022-40982 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.0CVE-2023-25756Intel atom x6200fe firmware out-of-bounds read vulnerabilityOut-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege vi…EPSS 0.40%6.4CVE-2022-21198Intel celeron 1000m firmware toctou race condition vulnerabilityTime-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalati…EPSS 0.15%5.5CVE-2020-8694Intel core i7-8510y firmware vulnerabilityInsufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information…EPSS 0.45%5.5CVE-2020-8695Intel core i7-8510y firmware observable discrepancy vulnerabilityObservable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure vi…EPSS 0.42%3.5CVE-2023-22329Intel atom x6200fe firmware improper input validation vulnerabilityImproper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service v…EPSS 0.30%2.4CVE-2022-0005Intel celeron g5205u firmware cleartext transmission vulnerabilitySensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potent…EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2022-40982), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.