Bug 2107465 (CVE-2022-28693)

Summary: CVE-2022-28693 hw: cpu: Intel: information disclosure via local access
Product: [Other] Security Response Reporter: TEJ RATHI <trathi>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: acaringi, adscvr, airlied, alciregi, amdas, bhu, chwhite, crwood, ddepaula, dvlasenk, hdegoede, hkrzesin, hpa, jarod, jarodwilson, jburrell, jfaracco, jferlan, jforbes, jglisse, jlelli, joe.lawrence, jonathan, josef, jshortt, jstancek, jwboyer, jwyatt, kcarcia, kernel-maint, kernel-mgr, lgoncalv, linville, llong, lzampier, masami256, mcascell, mchehab, nmurray, nsu, pmatouse, ptalbert, qzhao, rvrbovsk, scweaver, steved, tyberry, vkumar, walters, wcosta, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in hw. The unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to enable information disclosure via local access.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2108572, 2108573, 2108574, 2108575, 2108576, 2108577, 2108584    
Bug Blocks: 2058387    

Description TEJ RATHI 2022-07-15 06:58:34 UTC
Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00707.html
https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/return-stack-buffer-underflow.html

Comment 3 Petr Matousek 2022-07-19 11:35:34 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2108584]

Comment 4 Wander 2022-07-28 14:28:40 UTC
IIUC, this is a duplicate of BZ2090226.