CVE-2023-28746

Name
CVE-2023-28746
Description
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secure@intel.com https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00898.html
secure@intel.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A/
secure@intel.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG/
secure@intel.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK/
secure@intel.com http://www.openwall.com/lists/oss-security/2024/03/12/13
secure@intel.com https://lists.debian.org/debian-lts-announce/2024/05/msg00003.html
https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
af854a3a-2127-422b-91ae-364da2661108 http://xenbits.xen.org/xsa/advisory-452.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-265688.html

Match rules

CPE URI Source package Min version Max version
intel(r)-atom(r)-processors == See references == See references

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
xen edge-main 4.18.0-r5 Natanael Copa <ncopa@alpinelinux.org> fixed
xen 3.22-main 4.18.0-r5 None fixed
xen 3.21-main 4.18.0-r5 None fixed
xen 3.20-main 4.18.0-r5 None fixed
xen 3.19-main 4.18.0-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
xen 3.18-main 4.17.3-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
xen 3.17-main 4.16.5-r7 Natanael Copa <ncopa@alpinelinux.org> fixed
intel-ucode edge-main 20240312-r0 Marian Buschsieweke <marian.buschsieweke@ovgu.de> fixed
intel-ucode edge-main 20240312-40 None fixed
intel-ucode 3.22-main 20240312-r0 None fixed
intel-ucode 3.21-main 20240312-r0 None fixed
intel-ucode 3.20-main 20240312-r0 None fixed
intel-ucode 3.19-main 20240312-r0 None fixed
intel-ucode 3.18-main 20240813-r0 Marian Buschsieweke <marian.buschsieweke@posteo.net> fixed
intel-ucode 3.17-main 20240813-r0 Marian Buschsieweke <marian.buschsieweke@posteo.net> fixed