CVE-2022-40982

Vulnerability updated 8 months ago (2024-11-29T14:25:27.068Z)
Download STIX
Preview STIX
CVE-2022-40982, also known as "Downfall," is a significant software vulnerability discovered in Intel processors. Revealed by Google researchers, this side-channel attack targets memory optimization within Intel Core processors from the 6th to 11th generations, and Xeon Intel x86-64 CPUs from the 1st through 4th generations. The flaw exposes these chips to potential security breaches via local access, putting a vast range of devices at risk. The Downfall vulnerability was publicly disclosed on August 8, 2023, following intensive research and analysis. It is part of a series of newly discovered vulnerabilities affecting CPUs, including Zenbleed (CVE-2023-20593) which affects AMD's Zen 2 architecture-based processors, and others named Collide+Power (CVE-2023-20583) and Inception (CVE-2023-20569). These vulnerabilities represent a broad spectrum of threats to CPU security, with Downfall being particularly concerning due to its impact on widely used Intel processors. Also known as Gather Data Sampling (GDS), Downfall presents a serious challenge to the security of affected Intel processors. The vulnerability lies in the design and implementation of the software, creating a potential avenue for attackers to exploit. As such, it is critical for users of the affected processors to apply any available patches or updates to mitigate the risk associated with this vulnerability.
Description last updated: 2024-05-04T16:13:26.973Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2022-40982 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CISA
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago