PT-2022-24012 · Ampere · Ampere Altra+1

Published

2022-08-17

·

Updated

2022-08-18

·

CVE-2022-37459

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ampere Altra devices before 1.08g Ampere Altra Max devices before 2.05a
Description The issue allows attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, also known as a "Retbleed" issue.
Recommendations For Ampere Altra devices before 1.08g, update to version 1.08g or later to resolve the issue. For Ampere Altra Max devices before 2.05a, update to version 2.05a or later to resolve the issue.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2022-37459

Affected Products

Ampere Altra
Ampere Altra Max