vulnerability
VMSA-2022-0020: Return-Stack-Buffer-Underflow and Branch Type Confusion vulnerabilities (CVE-2022-26373)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:C/I:N/A:N) | Jul 12, 2022 | Sep 12, 2022 | Jun 24, 2026 |
Severity
5
CVSS
(AV:L/AC:L/Au:S/C:C/I:N/A:N)
Published
Jul 12, 2022
Added
Sep 12, 2022
Modified
Jun 24, 2026
Description
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Solutions
vmware-esxi65-upgrade-19997716vmware-esxi67-upgrade-19997733vmware-esxi700-upgrade-20036589vmware-esxi701-upgrade-20036589vmware-esxi702-upgrade-20036589vmware-esxi703-upgrade-20036589
References
- CVE-2022-26373
- https://attackerkb.com/topics/CVE-2022-26373
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.html
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html
- https://security.netapp.com/advisory/ntap-20221007-0005/
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00706.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-30932
- EUVD-EUVD-2022-30932
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.