CVE-2022-40982

Exp

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Published: 2023-08-11 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2022-40982 is rated High Exploit Risk (75.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.91%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.13% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2022-40982

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2022-40982

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.78% 3.91% +3.13%
2 2026-06-07 0.73% 0.78% +0.05%
3 2026-05-04 0.73%

Full EPSS history (25 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2022-40982

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.5 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
2.0 4.0 [email protected]
6.5 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
2.0 4.0 [email protected]

Weakness enumeration for CVE-2022-40982

OS Trackers for CVE-2022-40982

vendor priority summary link
alpine medium CVE-2022-40982: 2 source package rows (intel-ucode, xen); 14 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 14, open 0. https://security.alpinelinux.org/vuln/CVE-2022-40982
debian not yet assigned CVE-2022-40982 not yet assigned priority: Debian including 2 source packages (intel-microcode, linux), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 10. https://security-tracker.debian.org/tracker/CVE-2022-40982
redhat medium https://access.redhat.com/security/cve/CVE-2022-40982
suse medium https://www.suse.com/security/cve/CVE-2022-40982/
ubuntu medium CVE-2022-40982 medium priority: Ubuntu including 168 source packages (intel-microcode, linux, …), 1885 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 1428, released 245, not-affected 114, ignored 97, needed 1. https://ubuntu.com/security/CVE-2022-40982

Affected software / configurations for CVE-2022-40982

Vendor Product Version Raw CPE
redhat enterprise_linux 6.0 cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
redhat enterprise_linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
redhat enterprise_linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
redhat enterprise_linux 9.0 cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
xen xen cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:*
intel microcode < 20230808 cpe:2.3:o:intel:microcode:*:*:*:*:*:*:*:*
intel xeon_e-2314_firmware cpe:2.3:o:intel:xeon_e-2314_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2324g_firmware cpe:2.3:o:intel:xeon_e-2324g_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2334_firmware cpe:2.3:o:intel:xeon_e-2334_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2374g_firmware cpe:2.3:o:intel:xeon_e-2374g_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2336_firmware cpe:2.3:o:intel:xeon_e-2336_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2356g_firmware cpe:2.3:o:intel:xeon_e-2356g_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2386g_firmware cpe:2.3:o:intel:xeon_e-2386g_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2378_firmware cpe:2.3:o:intel:xeon_e-2378_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2378g_firmware cpe:2.3:o:intel:xeon_e-2378g_firmware:-:*:*:*:*:*:*:*
intel xeon_e-2388g_firmware cpe:2.3:o:intel:xeon_e-2388g_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1350_firmware cpe:2.3:o:intel:xeon_w-1350_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1350p_firmware cpe:2.3:o:intel:xeon_w-1350p_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1370_firmware cpe:2.3:o:intel:xeon_w-1370_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1370p_firmware cpe:2.3:o:intel:xeon_w-1370p_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1390t_firmware cpe:2.3:o:intel:xeon_w-1390t_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1390_firmware cpe:2.3:o:intel:xeon_w-1390_firmware:-:*:*:*:*:*:*:*
intel xeon_w-1390p_firmware cpe:2.3:o:intel:xeon_w-1390p_firmware:-:*:*:*:*:*:*:*
intel core_i9-11900t_firmware cpe:2.3:o:intel:core_i9-11900t_firmware:-:*:*:*:*:*:*:*
intel core_i9-11900f_firmware cpe:2.3:o:intel:core_i9-11900f_firmware:-:*:*:*:*:*:*:*
intel core_i9-11900_firmware cpe:2.3:o:intel:core_i9-11900_firmware:-:*:*:*:*:*:*:*
intel core_i9-11900kf_firmware cpe:2.3:o:intel:core_i9-11900kf_firmware:-:*:*:*:*:*:*:*
intel core_i9-11900k_firmware cpe:2.3:o:intel:core_i9-11900k_firmware:-:*:*:*:*:*:*:*
intel core_i7-11700t_firmware cpe:2.3:o:intel:core_i7-11700t_firmware:-:*:*:*:*:*:*:*
intel core_i7-11700f_firmware cpe:2.3:o:intel:core_i7-11700f_firmware:-:*:*:*:*:*:*:*
intel core_i7-11700_firmware cpe:2.3:o:intel:core_i7-11700_firmware:-:*:*:*:*:*:*:*
intel core_i7-11700kf_firmware cpe:2.3:o:intel:core_i7-11700kf_firmware:-:*:*:*:*:*:*:*
intel core_i7-11700k_firmware cpe:2.3:o:intel:core_i7-11700k_firmware:-:*:*:*:*:*:*:*
intel core_i5-11400t_firmware cpe:2.3:o:intel:core_i5-11400t_firmware:-:*:*:*:*:*:*:*
intel core_i5-11400f_firmware cpe:2.3:o:intel:core_i5-11400f_firmware:-:*:*:*:*:*:*:*
intel core_i5-11400_firmware cpe:2.3:o:intel:core_i5-11400_firmware:-:*:*:*:*:*:*:*
intel core_i5-11500t_firmware cpe:2.3:o:intel:core_i5-11500t_firmware:-:*:*:*:*:*:*:*
intel core_i5-11500_firmware cpe:2.3:o:intel:core_i5-11500_firmware:-:*:*:*:*:*:*:*
intel core_i5-11600t_firmware cpe:2.3:o:intel:core_i5-11600t_firmware:-:*:*:*:*:*:*:*
intel core_i5-11600_firmware cpe:2.3:o:intel:core_i5-11600_firmware:-:*:*:*:*:*:*:*
intel core_i5-11600kf_firmware cpe:2.3:o:intel:core_i5-11600kf_firmware:-:*:*:*:*:*:*:*
intel core_i5-11600k_firmware cpe:2.3:o:intel:core_i5-11600k_firmware:-:*:*:*:*:*:*:*
intel celeron_g5900t_firmware cpe:2.3:o:intel:celeron_g5900t_firmware:-:*:*:*:*:*:*:*
intel celeron_g5920_firmware cpe:2.3:o:intel:celeron_g5920_firmware:-:*:*:*:*:*:*:*
intel celeron_g5900_firmware cpe:2.3:o:intel:celeron_g5900_firmware:-:*:*:*:*:*:*:*
intel celeron_g5925_firmware cpe:2.3:o:intel:celeron_g5925_firmware:-:*:*:*:*:*:*:*
intel celeron_g5905t_firmware cpe:2.3:o:intel:celeron_g5905t_firmware:-:*:*:*:*:*:*:*
intel celeron_g5905_firmware cpe:2.3:o:intel:celeron_g5905_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6500t_firmware cpe:2.3:o:intel:pentium_gold_g6500t_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6600_firmware cpe:2.3:o:intel:pentium_gold_g6600_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6400t_firmware cpe:2.3:o:intel:pentium_gold_g6400t_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6400_firmware cpe:2.3:o:intel:pentium_gold_g6400_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6500_firmware cpe:2.3:o:intel:pentium_gold_g6500_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6605_firmware cpe:2.3:o:intel:pentium_gold_g6605_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6505t_firmware cpe:2.3:o:intel:pentium_gold_g6505t_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6505_firmware cpe:2.3:o:intel:pentium_gold_g6505_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6405_firmware cpe:2.3:o:intel:pentium_gold_g6405_firmware:-:*:*:*:*:*:*:*
intel pentium_gold_g6405t_firmware cpe:2.3:o:intel:pentium_gold_g6405t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100t_firmware cpe:2.3:o:intel:core_i3-10100t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100_firmware cpe:2.3:o:intel:core_i3-10100_firmware:-:*:*:*:*:*:*:*
intel core_i3-10300t_firmware cpe:2.3:o:intel:core_i3-10300t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10300_firmware cpe:2.3:o:intel:core_i3-10300_firmware:-:*:*:*:*:*:*:*
intel core_i3-10320_firmware cpe:2.3:o:intel:core_i3-10320_firmware:-:*:*:*:*:*:*:*
intel core_i3-10100f_firmware cpe:2.3:o:intel:core_i3-10100f_firmware:-:*:*:*:*:*:*:*
intel core_i3-10105_firmware cpe:2.3:o:intel:core_i3-10105_firmware:-:*:*:*:*:*:*:*
intel core_i3-10305_firmware cpe:2.3:o:intel:core_i3-10305_firmware:-:*:*:*:*:*:*:*
intel core_i3-10305t_firmware cpe:2.3:o:intel:core_i3-10305t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10105t_firmware cpe:2.3:o:intel:core_i3-10105t_firmware:-:*:*:*:*:*:*:*
intel core_i3-10325_firmware cpe:2.3:o:intel:core_i3-10325_firmware:-:*:*:*:*:*:*:*
intel core_i3-10105f_firmware cpe:2.3:o:intel:core_i3-10105f_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600_firmware cpe:2.3:o:intel:core_i5-10600_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400_firmware cpe:2.3:o:intel:core_i5-10400_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400f_firmware cpe:2.3:o:intel:core_i5-10400f_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500_firmware cpe:2.3:o:intel:core_i5-10500_firmware:-:*:*:*:*:*:*:*
intel core_i5-10400t_firmware cpe:2.3:o:intel:core_i5-10400t_firmware:-:*:*:*:*:*:*:*
intel core_i5-10500t_firmware cpe:2.3:o:intel:core_i5-10500t_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600t_firmware cpe:2.3:o:intel:core_i5-10600t_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600kf_firmware cpe:2.3:o:intel:core_i5-10600kf_firmware:-:*:*:*:*:*:*:*
intel core_i5-10600k_firmware cpe:2.3:o:intel:core_i5-10600k_firmware:-:*:*:*:*:*:*:*
intel core_i5-10505_firmware cpe:2.3:o:intel:core_i5-10505_firmware:-:*:*:*:*:*:*:*

References for CVE-2022-40982

URL Tags
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html Exploit Mitigation Vendor Advisory
https://access.redhat.com/solutions/7027704 Third Party Advisory
https://aws.amazon.com/security/security-bulletins/AWS-2023-007/ Third Party Advisory
https://downfall.page Exploit Technical Description Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00013.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/
https://lists.fedoraproject.org/archives/list/[email protected]/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/
https://lists.fedoraproject.org/archives/list/[email protected]/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/
https://security.netapp.com/advisory/ntap-20230811-0001/ Third Party Advisory
https://www.debian.org/security/2023/dsa-5474 Mailing List Third Party Advisory
https://www.debian.org/security/2023/dsa-5475 Mailing List Third Party Advisory
https://xenbits.xen.org/xsa/advisory-435.html Mitigation Third Party Advisory
http://xenbits.xen.org/xsa/advisory-435.html
cvelogic Threat Intelligence