Bug 2476541 (CVE-2025-35979) - CVE-2025-35979 kernel: Kernel: Information disclosure via shared microarchitectural predictor state in Intel(R) Processors
Summary: CVE-2025-35979 kernel: Kernel: Information disclosure via shared microarchite...
Keywords:
Status: NEW
Alias: CVE-2025-35979
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-12 17:02 UTC by OSIDB Bzimport
Modified: 2026-05-29 14:01 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-12 17:02:00 UTC
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.


Note You need to log in before you can comment on or make changes to this bug.