CVE-2023-38575 is a medium-severity information disclosure vulnerability affecting some Intel processors, stemming from non-transparent sharing of return predictor targets between contexts. An authorized local user could exploit this with low attack complexity to potentially disclose sensitive information. While not actively exploited and lacking public exploit code, it has garnered some community discussion and media coverage, including a report of its impact on Linux systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Intel(R) Processors | some Intel(R) ProcessorsCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.