# CVE-2022-40982

## Summary

- **CVE ID:** CVE-2022-40982
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-1342
- **Published:** Aug 11, 2023
- **Last Modified:** Mar 13, 2026

## Description

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

## Affected Products

- n/a — Intel(R) Processors (See references)

## References

- [CNA](http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html)
- [CNA](https://downfall.page)
- [CNA](https://aws.amazon.com/security/security-bulletins/AWS-2023-007/)
- [CNA](https://access.redhat.com/solutions/7027704)
- [CNA](https://xenbits.xen.org/xsa/advisory-435.html)
- [CNA](https://lists.debian.org/debian-lts-announce/2023/08/msg00013.html)
- [CNA](https://security.netapp.com/advisory/ntap-20230811-0001/)
- [CNA](https://www.debian.org/security/2023/dsa-5474)
- [CNA](https://www.debian.org/security/2023/dsa-5475)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/)
- [CNA](https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/)
- [CVE](http://xenbits.xen.org/xsa/advisory-435.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.79%
- **EPSS Percentile:** 73.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._