PT-2023-4328 · Intel+9 · Intel Processors+9

Daniel Moghimi

·

Published

2023-08-08

·

Updated

2025-09-26

·

CVE-2022-40982

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intel Processors versions prior to the fixed version
Description The issue is related to information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors. This may allow an authenticated user to potentially enable information disclosure via local access. The vulnerability, known as Downfall, affects Intel consumer and server processors ranging from the Skylake family to Rocket Lake. It enables a user to access and steal data from other users who share the same computer. The vulnerability is caused by memory optimization features in Intel processors that unintentionally reveal internal data.
Recommendations To resolve the issue, update the microcode to the latest version. However, this may lead to a loss of performance. For mitigation, consider disabling the gather instruction, which is used in the Downfall attack, until a patch is available. Additionally, restrict access to sensitive data and use secure communication protocols to minimize the risk of exploitation.
Note: The exact mitigation measures may vary depending on the specific system configuration and the affected Intel processor version. It is recommended to consult the official Intel documentation and security advisories for detailed guidance on resolving the issue.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:7077
ALT-PU-2023-4844
ALT-PU-2023-5044
ALT-PU-2023-7281
ALT-PU-2023-7691
ALT-PU-2023-8026
ALT-PU-2023-8027
BDU:2023-04663
CESA-2023_6901
CESA-2023_7077
CESA-2023_7423
CVE-2022-40982
DLA-3524-1
DLA-3525-1
DLA-3537-1
DSA-5474-1
DSA-5475-1
MGASA-2023-0249
MGASA-2023-0250
MGASA-2023-0251
OESA-2023-1548
OESA-2023-1549
OESA-2023-1550
OESA-2023-1553
OESA-2023-1554
OPENSUSE-SU-2023_3302-1
OPENSUSE-SU-2023_3311-1
OPENSUSE-SU-2023_3313-1
OPENSUSE-SU-2023_3318-1
OPENSUSE-SU-2023_3376-1
OPENSUSE-SU-2023_3377-1
OPENSUSE-SU-2023_3383-1
OPENSUSE-SU-2023_3391-1
OPENSUSE-SU-2023_3392-1
OPENSUSE-SU-2023_3395-1
OPENSUSE-SU-2023_3447-1
OPENSUSE-SU-2024:13112-1
OPENSUSE-SU-2024:13115-1
OPENSUSE-SU-2024:13122-1
OPENSUSE-SU-2024:13704-1
RHSA-2023:6583
RHSA-2023:6901
RHSA-2023:7077
RHSA-2023:7370
RHSA-2023:7379
RHSA-2023:7423
RHSA-2023:7424
RHSA-2023:7539
RHSA-2023_6583
RHSA-2023_6901
RHSA-2023_7077
RHSA-2023_7423
RHSA-2023_7424
RHSA-2024:0412
RHSA-2024:0562
RHSA-2024:0563
RHSA-2024:1250
RHSA-2024:1268
RHSA-2024:1269
RHSA-2024:1306
RHSA-2024:3319
ROSA-SA-2025-2872
SUSE-SU-2023:3289-1
SUSE-SU-2023:3302-1
SUSE-SU-2023:3309-1
SUSE-SU-2023:3311-1
SUSE-SU-2023:3313-1
SUSE-SU-2023:3318-1
SUSE-SU-2023:3324-1
SUSE-SU-2023:3329-1
SUSE-SU-2023:3333-1
SUSE-SU-2023:3349-1
SUSE-SU-2023:3359-1
SUSE-SU-2023:3376-1
SUSE-SU-2023:3377-1
SUSE-SU-2023:3382-1
SUSE-SU-2023:3383-1
SUSE-SU-2023:3390-1
SUSE-SU-2023:3391-1
SUSE-SU-2023:3392-1
SUSE-SU-2023:3395-1
SUSE-SU-2023:3421-1
SUSE-SU-2023:3446-1
SUSE-SU-2023:3447-1
SUSE-SU-2023:3494-1
SUSE-SU-2023:3495-1
SUSE-SU-2023:3496-1
SUSE-SU-2023:3894-1
SUSE-SU-2023:3895-1
SUSE-SU-2023:3902-1
SUSE-SU-2023_3289-1
SUSE-SU-2023_3309-1
SUSE-SU-2023_3311-1
SUSE-SU-2023_3313-1
SUSE-SU-2023_3329-1
SUSE-SU-2023_3359-1
SUSE-SU-2023_3376-1
SUSE-SU-2023_3377-1
SUSE-SU-2023_3382-1
SUSE-SU-2023_3383-1
SUSE-SU-2023_3395-1
SUSE-SU-2023_3447-1
SUSE-SU-2023_3494-1
SUSE-SU-2023_3495-1
SUSE-SU-2023_3496-1
SUSE-SU-2023_3894-1
SUSE-SU-2023_3895-1
SUSE-SU-2023_3902-1
SUSE-SU-2025:1032-1
SUSE-SU-2025_1032-1
USN-6286-1
USN-6315-1
USN-6316-1
USN-6317-1
USN-6318-1
USN-6321-1
USN-6324-1
USN-6325-1
USN-6328-1
USN-6329-1
USN-6330-1
USN-6331-1
USN-6332-1
USN-6346-1
USN-6348-1
USN-6357-1
USN-6388-1
USN-6396-1
USN-6396-2
USN-6396-3
USN-6397-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Intel Processors
Linuxmint
Red Hat
Red Os
Suse
Ubuntu