CVE-2022-26373 is a moderate-severity information-disclosure flaw in certain Intel processors that support Enhanced Indirect Branch Restricted Speculation (eIBRS). Following a VM exit or an Indirect Branch Prediction Barrier (IBPB) event, an unbalanced near RET can be predicted using the address after the most recent near CALL executed before the VM exit, until the first post-barrier CALL retires. This speculative behavior can expose sensitive information; Red Hat assigned CVSS 5.5, requiring local, low-privileged access and affecting confidentiality rather than integrity or availability.
Operating systems and virtual-machine monitors that execute affected unbalanced return instructions require a short software mitigation, while implementations using Return Stack Buffer stuffing are not affected. Fedora corrected the issue in stable kernel 5.18.17, and Red Hat released kernel and kernel-rt updates for affected RHEL 7, 8, and 9 streams, including relevant EUS releases and Red Hat Virtualization 4 on RHEL 8. Organizations should apply the vendor kernel updates and assess hypervisor and guest workloads for reliance on vulnerable RSB behavior.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2022:7337 and RHSA-2022:7338 to fix the RHEL 7 kernel and kernel-rt packages affected by CVE-2022-26373.
Red Hat released RHSA-2022:7110 to remediate CVE-2022-49611 in RHEL 8 kernel packages and Red Hat Virtualization 4 for RHEL 8. The fix fills the Return Stack Buffer on virtual-machine exit when IBRS is in use.
Red Hat published CVE-2022-26373, an information-disclosure vulnerability involving post-barrier Return Stack Buffer predictions on certain Intel processors with eIBRS.
Red Hat released RHSA-2023:0440, fixing CVE-2022-26373 for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8 kernel.
Red Hat closed its tracking bug for CVE-2022-26373.
Red Hat released RHSA-2022:8973 and RHSA-2022:8974, providing kernel and kernel-rt fixes for CVE-2022-26373 in RHEL 9.0 Extended Update Support.
Red Hat released RHSA-2022:8267 and RHSA-2022:7933 to remediate CVE-2022-26373 in the RHEL 9 kernel and kernel-rt packages.
Red Hat released RHSA-2022:7683 and RHSA-2022:7444 to fix the RHEL 8 kernel and kernel-rt packages for CVE-2022-26373.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.