BDU:2022-05155
Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3,8) Средний уровень опасности (базовая оценка CVSS 3.0 составляет 5,6) CVSS 5.599999904632568 · AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NУязвимость системы ввода-вывода с отображением памяти (MMIO) процессоров Intel, позволяющая нарушителю раскрыть защищаемую информацию
Отчёты сканеров говорят на языке CVE, требования регуляторов — на языке БДУ. Перевести список из отчёта →
Описание
Уязвимость системы ввода-вывода с отображением памяти (MMIO) процессоров Intel связана с раскрытием информации. Эксплуатация уязвимости может позволить нарушителю раскрыть защищаемую информацию
Способ устранения
Использование рекомендаций: Для Intel: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html Для VMware: https://www.vmware.com/security/advisories/VMSA-2022-0016.html https://kb.vmware.com/s/article/88632 Для Linux (Oracle Corp.): https://www.oracle.com/security-alerts/linuxbulletinjul2022.html Для программных продуктов Microsoft Corp.: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21125 Для ядра Linux: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4419470191386456e0b8ed4eb06a70b0021798a6 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.5 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.123 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.48 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.199 https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.319 https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.284 https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.248 Для программных продуктов Citrix Systems, Inc..: https://support.citrix.com/article/CTX460064/citrix-hypervisor-security-update https://support.citrix.com/article/CTX459953/hotfix-xs71ecu2075-for-xenserver-71-cumulative-update-2 https://security.gentoo.org/glsa/202208-23 Для Fedora: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHTEW3RXU2GW6S3RCPQG4VNCZGI3TOSV/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MCVOMHBQRH4KP7IN6U24CW7F2D2L5KBS/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4P2KJYL74KGLHE4JZETVW7PZH6ZIABA/ Для программных продуктов Red Hat Inc.: https://access.redhat.com/security/cve/cve-2022-21125 Для Debian GNU/Linux: https://security-tracker.debian.org/tracker/CVE-2022-21125 Для Ubuntu: https://ubuntu.com/security/CVE-2022-21125 Для программных продуктов Novell Inc.: https://www.suse.com/security/cve/CVE-2022-21125.html Для ОС Astra Linux: использование рекомендаций производителя: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2022-0819SE17 https://wiki.astralinux.ru/astra-linux-se16-bulletin-20220829SE16 Для ОСОН ОСнова Оnyx: Обновление программного обеспечения xen до версии 4.16.2-1 Для ОСОН ОСнова Оnyx (версия 2.7): Обновление программного обеспечения linux до версии 5.15.86-1.osnova211
Сведения записи
Уязвимое программное обеспечение
| Производитель | Название | Версия | Платформа |
|---|---|---|---|
| Broadcom Inc. | VMware Cloud Foundation | от 3.0 до KB88707 | Не указана |
| Broadcom Inc. | VMware Cloud Foundation | от 4.0 до KB88695 | Не указана |
| Broadcom Inc. | VMware ESXi | от 6.5 до ESXi 7.0 U3e | Не указана |
| Broadcom Inc. | VMware ESXi | от 6.7 до ESXi 6.7 U3r | Не указана |
| Broadcom Inc. | VMware ESXi | от 7.0 до ESXi 7.0 U3e | Не указана |
| Canonical Ltd. | Ubuntu | 14.04 ESM | Не указана |
| Canonical Ltd. | Ubuntu | 16.04 ESM | Не указана |
| Canonical Ltd. | Ubuntu | 18.04 LTS | Не указана |
| Canonical Ltd. | Ubuntu | 20.04 LTS | Не указана |
| Canonical Ltd. | Ubuntu | 21.10 | Не указана |
| Canonical Ltd. | Ubuntu | 22.04 LTS | Не указана |
| Fedora Project | Fedora | 35 | Не указана |
| Fedora Project | Fedora | 36 | Не указана |
| Intel Corp. | Intel SGX DCAP | до 1.14.100.3 | Linux |
| Intel Corp. | Intel SGX DCAP | до 1.14.100.3 | Windows |
| Intel Corp. | Intel SGX PSW | до 2.16.100.3 | Windows |
| Intel Corp. | Intel SGX PSW | до 2.17.100.3 | Linux |
| Intel Corp. | Intel SGX SDK for Linux | до 2.17.100.3 | Не указана |
| Intel Corp. | Intel SGX SDK for Windows | до 2.16.100.3 | Не указана |
| Microsoft Corp | Windows 10 | - | 32-bit |
| Microsoft Corp | Windows 10 | - | 64-bit |
| Microsoft Corp | Windows 10 1607 | - | 32-bit |
| Microsoft Corp | Windows 10 1607 | - | 64-bit |
| Microsoft Corp | Windows 10 1809 | - | ARM64 |
| Microsoft Corp | Windows 10 1809 | - | 32-bit |
| Microsoft Corp | Windows 10 1809 | - | 64-bit |
| Microsoft Corp | Windows 10 20H2 | - | 64-bit |
| Microsoft Corp | Windows 10 20H2 | - | ARM64 |
| Microsoft Corp | Windows 10 20H2 | - | 32-bit |
| Microsoft Corp | Windows 10 21H1 | - | 64-bit |
| Microsoft Corp | Windows 10 21H1 | - | 32-bit |
| Microsoft Corp | Windows 10 21H1 | - | ARM64 |
| Microsoft Corp | Windows 10 21H2 | - | 64-bit |
| Microsoft Corp | Windows 10 21H2 | - | 32-bit |
| Microsoft Corp | Windows 10 21H2 | - | ARM64 |
| Microsoft Corp | Windows 11 | - | 64-bit |
| Microsoft Corp | Windows 11 | - | ARM64 |
| Microsoft Corp | Windows 7 Service Pack 1 | - | 32-bit |
| Microsoft Corp | Windows 7 Service Pack 1 | - | 64-bit |
| Microsoft Corp | Windows 8.1 | - | 32-bit |
| Microsoft Corp | Windows 8.1 | - | 64-bit |
| Microsoft Corp | Windows RT 8.1 | - | Не указана |
| Microsoft Corp | Windows Server 2008 R2 Service Pack 1 | - | 64-bit |
| Microsoft Corp | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | - | 64-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 | - | 32-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 | - | 64-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 (Server Core Installation) | - | 32-bit |
| Microsoft Corp | Windows Server 2008 Service Pack 2 (Server Core Installation) | - | 64-bit |
| Microsoft Corp | Windows Server 2012 | - | Не указана |
| Microsoft Corp | Windows Server 2012 (Server Core installation) | - | Не указана |
Показано 50 из 112 записей — полный перечень в первоисточнике.
Чтобы такие записи находились не вручную, ведите реестр программного обеспечения: в личном кабинете уязвимости сопоставляются с вашим ПО, а работы по устранению попадают в план. Завести кабинет →
Источник: Банк данных угроз безопасности информации ФСТЭК России. Данные выгружены 17.08.2026, записей в справочнике — 92920. Справочник не является официальным ресурсом ФСТЭК России: сверяйте сведения с первоисточником.