Intel, Microsoft, VMware, Xen, and Linux maintainers published mitigation guidance for Downfall / Gather Data Sampling (GDS), a transient execution side-channel vulnerability tracked as CVE-2022-40982 that affects multiple Intel processor generations from Skylake through Tiger Lake/Ice Lake-era parts. Research by Google’s Daniel Moghimi showed the flaw can leak sensitive data across security boundaries—including processes, the kernel, virtual machines, sibling threads, and some trusted execution environments—by abusing speculative execution of gather instructions to expose stale vector register contents. Reported impacts include theft of passwords, encryption keys, SGX-protected data, and other memory-derived secrets, with shared and cloud environments highlighted as particularly exposed.
Intel said mitigation relies primarily on updated microcode that blocks transient results of gather instructions from being observed speculatively, while Microsoft directed Windows customers to obtain Intel platform updates from OEMs and noted the protection is enabled by default. VMware said hypervisor patches are generally not required if underlying firmware is updated, while Xen issued advisory XSA-435 and stable-tree fixes plus options such as restricting AVX for untrusted guests. Intel and downstream guidance warned that mitigation can carry noticeable performance costs—minimal for many workloads but up to 50% for gather-heavy applications—and added that newer Intel families such as Alder Lake, Raptor Lake, and Sapphire Rapids include protections and are not considered affected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
The Linux kernel documentation published an administrative guide for Gather Data Sampling, providing platform-specific documentation for the vulnerability and its handling in Linux environments. This reflects ongoing ecosystem documentation after the original disclosure.
Microsoft published KB5029778 with guidance for managing Gather Data Sampling on supported Windows systems running on affected Intel CPUs. It recommended Intel Platform Update 23.3 microcode from OEMs and stated the mitigation is enabled by default with no option to disable it.
Intel later published expanded technical documentation describing how the GDS microcode mitigation works, default enablement, MSR controls, SGX requirements, Key Locker exposure, and guidance for Linux, Windows, and virtualized environments. The documentation also reiterated that some gather-heavy workloads may see performance degradation of up to 50%.
Intel published a threat analysis for Gather Data Sampling assessing practical exploitability across deployment scenarios such as trusted systems, HPC, and multi-tenant cloud environments. The guidance said Intel was not aware of exploitation outside laboratory settings and advised administrators to balance threat exposure against potential performance impact when deciding whether to keep mitigations enabled.
Follow-up reporting highlighted that Intel's Downfall mitigations could significantly reduce performance, with some tests showing drops up to 39% and Intel warning certain workloads could see even higher impact. This clarified the operational tradeoffs of deploying the microcode fix.
Xen issued Security Advisory 435 for CVE-2022-40982, stating all Xen versions are affected on vulnerable Intel processors. Xen released fixes in stable versions 4.17.2, 4.16.5, 4.15.5, and 4.14.6, and also documented AVX-disabling mitigations.
VMware stated its hypervisors may be affected only when running on impacted Intel processors, but that VMware hypervisor patches were not required for remediation. Customers were directed to review Intel's advisory and obtain firmware updates from hardware vendors if needed.
At disclosure, Intel released microcode updates to mitigate CVE-2022-40982 on affected processors. Intel noted the mitigation is enabled by default and may impose substantial overhead on some gather-heavy workloads.
Intel disclosed Gather Data Sampling on August 8, 2023, and Google researcher Daniel Moghimi publicly unveiled the Downfall attacks the same day. Public reporting described data leakage risks across processes, VMs, and SGX boundaries on affected Intel CPU generations.
Intel published advisory guidance for Gather Data Sampling, documenting the transient execution flaw and vendor guidance for affected processors. This marks Intel's public advisory for CVE-2022-40982.
A public Downfall project site was published, indicating coordinated public-facing material for the vulnerability. The exact event details are not provided in the reference beyond the site's existence.
Daniel Moghimi reported the Gather Data Sampling / Downfall vulnerability to Intel in August 2022. The issue was later tracked as CVE-2022-40982.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
kernel.org
Open sourcesupport.microsoft.com
Open sourceintel.com
Open sourceintel.com
Open sourcetechtarget.com
Open sourcebleepingcomputer.com
Open sourceintel.com
Open sourcedownfall.page
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.