CVE Vulnerabilities

CVE-2022-21127

Incomplete Cleanup

Published: Jun 15, 2022 | Modified: May 05, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.6 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
XenXen**
Intel-microcodeUbuntubionic*
Intel-microcodeUbuntudevel*
Intel-microcodeUbuntuesm-infra-legacy/trusty*
Intel-microcodeUbuntuesm-infra/bionic*
Intel-microcodeUbuntuesm-infra/focal*
Intel-microcodeUbuntuesm-infra/xenial*
Intel-microcodeUbuntufocal*
Intel-microcodeUbuntuimpish*
Intel-microcodeUbuntujammy*
Intel-microcodeUbuntukinetic*
Intel-microcodeUbuntutrusty/esm*
Intel-microcodeUbuntuupstream*

Potential Mitigations

References