Rapid7

vulnerability

Red Hat: CVE-2022-29901: RetBleed Arbitrary Speculative Code Execution with Return Instructions (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:M/Au:N/C:P/I:N/A:N)
Published
Jul 12, 2022
Added
Oct 26, 2022
Modified
Mar 27, 2026

Description

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

Solutions

redhat-upgrade-kernelredhat-upgrade-kernel-rt

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.