BDU:2022-03532
Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5,2) Средний уровень опасности (базовая оценка CVSS 3.0 составляет 6,1) CVSS 6.099999904632568 · AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NУязвимость общих буферов системы ввода-вывода с отображением памяти (MMIO) процессоров Intel, позволяющая нарушителю раскрыть защищаемую информацию
Отчёты сканеров говорят на языке CVE, требования регуляторов — на языке БДУ. Перевести список из отчёта →
Описание
Уязвимость общих буферов системы ввода-вывода с отображением памяти (MMIO) процессоров Intel связана с раскрытием информации. Эксплуатация уязвимости может позволить нарушителю раскрыть защищаемую информацию
Способ устранения
Использование рекомендаций: Для Intel: https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/processor-mmio-stale-data-vulnerabilities.html https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html Для VMware: https://www.vmware.com/security/advisories/VMSA-2022-0016.html https://kb.vmware.com/s/article/88632 https://kb.vmware.com/s/article/88707 Для ядра Linux: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4419470191386456e0b8ed4eb06a70b0021798a6 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.9 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.41 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18 Для Linux (Oracle Corp.): https://linux.oracle.com/cve/CVE-2022-21123.html Для программных продуктов Red Hat Inc.: https://access.redhat.com/security/cve/cve-2022-21123 Для программных продуктов Novell Inc.: https://www.suse.com/security/cve/CVE-2022-21123.html Для Ubuntu: https://ubuntu.com/security/CVE-2022-21123 https://ubuntu.com/security/notices/USN-5484-1 https://ubuntu.com/security/notices/USN-5485-1 Для Debian GNU/Linux: https://security-tracker.debian.org/tracker/CVE-2022-21123 Для Fedora: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4P2KJYL74KGLHE4JZETVW7PZH6ZIABA/ Для программных продуктов Microsoft Corp.: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21123 Для ОС Astra Linux: использование рекомендаций производителя: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2022-0819SE17 https://wiki.astralinux.ru/astra-linux-se16-bulletin-20220829SE16 Для ОСОН ОСнова Оnyx: Обновление программного обеспечения xen до версии 4.16.2-1 Для ОСОН ОСнова Оnyx (версия 2.7): Обновление программного обеспечения linux до версии 5.15.86-1.osnova211
Сведения записи
Уязвимое программное обеспечение
| Производитель | Название | Версия | Платформа |
|---|---|---|---|
| Broadcom Inc. | VMware Cloud Foundation | 4.0 | Не указана |
| Broadcom Inc. | VMware Cloud Foundation | от 3.0 до KB88707 | Не указана |
| Broadcom Inc. | VMware ESXi | от 6.5 до ESXi 7.0 U3e | Не указана |
| Broadcom Inc. | VMware ESXi | от 6.7 до ESXi 6.7 U3r | Не указана |
| Broadcom Inc. | VMware ESXi | от 7.0 до ESXi 7.0 U3e | Не указана |
| Canonical Ltd. | Ubuntu | 14.04 ESM | Не указана |
| Canonical Ltd. | Ubuntu | 16.04 ESM | Не указана |
| Canonical Ltd. | Ubuntu | 18.04 LTS | Не указана |
| Canonical Ltd. | Ubuntu | 20.04 LTS | Не указана |
| Canonical Ltd. | Ubuntu | 21.10 | Не указана |
| Canonical Ltd. | Ubuntu | 22.04 LTS | Не указана |
| Fedora Project | Fedora | 35 | Не указана |
| Fedora Project | Fedora | 36 | Не указана |
| Intel Corp. | Intel SGX DCAP | до 1.14.100.3 | Не указана |
| Intel Corp. | Intel SGX PSW | до 2.16.100.3 для Windows | Не указана |
| Intel Corp. | Intel SGX PSW | до 2.17.100.3 для Linux | Не указана |
| Intel Corp. | Intel Software Guard Extensions SDK | до 2.16.100.3 для Windows | Не указана |
| Intel Corp. | Intel Software Guard Extensions SDK | до 2.17.100.3 для Linux | Не указана |
| Intel Corp. | Intel Xeon E3 | - | Не указана |
| Microsoft Corp | Windows 10 | - | 64-bit |
| Microsoft Corp | Windows 10 | - | 32-bit |
| Microsoft Corp | Windows 10 1607 | - | 32-bit |
| Microsoft Corp | Windows 10 1607 | - | 64-bit |
| Microsoft Corp | Windows 10 1809 | - | ARM64 |
| Microsoft Corp | Windows 10 1809 | - | 32-bit |
| Microsoft Corp | Windows 10 1809 | - | 64-bit |
| Microsoft Corp | Windows 10 20H2 | - | 32-bit |
| Microsoft Corp | Windows 10 20H2 | - | ARM64 |
| Microsoft Corp | Windows 10 20H2 | - | 64-bit |
| Microsoft Corp | Windows 10 21H1 | - | 32-bit |
| Microsoft Corp | Windows 10 21H1 | - | 64-bit |
| Microsoft Corp | Windows 10 21H1 | - | ARM64 |
| Microsoft Corp | Windows 10 21H2 | - | 64-bit |
| Microsoft Corp | Windows 10 21H2 | - | ARM64 |
| Microsoft Corp | Windows 10 21H2 | - | 32-bit |
| Microsoft Corp | Windows 11 | - | ARM64 |
| Microsoft Corp | Windows 11 | - | 64-bit |
| Microsoft Corp | Windows 7 Service Pack 1 | - | 32-bit |
| Microsoft Corp | Windows 7 Service Pack 1 | - | 64-bit |
| Microsoft Corp | Windows 8.1 | - | 32-bit |
| Microsoft Corp | Windows 8.1 | - | 64-bit |
| Microsoft Corp | Windows RT 8.1 | - | Не указана |
| Microsoft Corp | Windows Server 2008 R2 Service Pack 1 | - | 64-bit |
| Microsoft Corp | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | - | 64-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 | - | 32-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 | - | 64-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 (Server Core Installation) | - | 32-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 (Server Core Installation) | - | 64-bit |
| Microsoft Corp | Windows Server 2012 | - | Не указана |
| Microsoft Corp | Windows Server 2012 (Server Core installation) | - | Не указана |
Показано 50 из 104 записей — полный перечень в первоисточнике.
Чтобы такие записи находились не вручную, ведите реестр программного обеспечения: в личном кабинете уязвимости сопоставляются с вашим ПО, а работы по устранению попадают в план. Завести кабинет →
Источник: Банк данных угроз безопасности информации ФСТЭК России. Данные выгружены 17.08.2026, записей в справочнике — 92920. Справочник не является официальным ресурсом ФСТЭК России: сверяйте сведения с первоисточником.