AMD documented CVE-2022-23825, a medium-severity speculative-execution flaw affecting certain processor families. Branch-predictor aliasing can cause CPUs to incorrectly predict a branch type, enabling a local, low-privileged attacker to infer sensitive information through branch type confusion. The issue is related to Spectre Variant 2 research; AMD recommends that software developers apply its Branch Type Confusion mitigation guidance and reported no known active exploitation at disclosure.
Red Hat rates the vulnerability as moderate, assigning CVSS 3.1 score 5.6 versus the NVD score of 6.5 because exploitation complexity is high in its environments. Red Hat released updated kernel and kernel-rt packages for RHEL 7, 8, and 9, including RHEL 9.0 Extended Update Support and Red Hat Virtualization 4 on RHEL 8; RHEL 6 will not receive a fix. Organizations operating affected AMD systems should deploy vendor kernel updates and verify applicable speculative-execution mitigations are enabled.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released fixes for the RHEL 7 kernel and kernel-rt packages in RHSA-2022:7337 and RHSA-2022:7338.
Red Hat released RHEL 8 kernel and kernel-rt fixes for CVE-2022-23825 through RHSA-2022:7110 and RHSA-2022:7134. The RHSA-2022:7110 update also provided the kernel fix for Red Hat Virtualization 4 on RHEL 8.
AMD published AMD-SB-1037, disclosing CVE-2022-23825 (Branch Type Confusion) and CVE-2022-29900/RETbleed as medium-severity issues related to Spectre Variant 2. AMD recommended software mitigations and said it was unaware of active exploitation against AMD products related to CVE-2017-5715 at disclosure.
Red Hat designated the RHEL 6 kernel as will not fix for CVE-2022-23825 and recommended upgrading to a supported product version containing a fix.
Red Hat released CVE-2022-23825 fixes for the RHEL 9.0 Extended Update Support kernel and kernel-rt packages in RHSA-2022:8973 and RHSA-2022:8974.
Red Hat released RHEL 9 kernel and kernel-rt fixes for CVE-2022-23825 through RHSA-2022:8267 and RHSA-2022:7933.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.