Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NAmd Ryzen 5 5600x
HWAmdall versionsAmd Ryzen 7 2700x
HWAmdall versionsAmd Ryzen Threadripper 2990wx
HWAmdall versionsArm Cortex A72
HWArmall versionsBroadcom Bcm2711
HWBroadcomall versionsFedora Project Fedora
OSFedoraproject3334Intel Core I7 10700k
HWIntelall versionsIntel Core I7 7700k
HWIntelall versionsIntel Core I9 9900k
HWIntelall versionsIntel Xeon Silver 4214
HWIntelall versionsXen
OSXenall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox
CVE-2023-6345CRITICAL9.6⚠ KEVPL ✓same product
Integer overflow w Skia w Google Chrome — sandbox escape