Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitywidely-deployed-product-advisorycloud-service-vulnerabilitypatch-regression

Downfall CPU flaw exposes data on affected Intel systems via Gather Data Sampling

Updated 28d agoFirst seen May 25, 202612 sources

Intel, Microsoft, VMware, Xen, and Linux maintainers published mitigation guidance for Downfall / Gather Data Sampling (GDS), a transient execution side-channel vulnerability tracked as CVE-2022-40982 that affects multiple Intel processor generations from Skylake through Tiger Lake/Ice Lake-era parts. Research by Google’s Daniel Moghimi showed the flaw can leak sensitive data across security boundaries—including processes, the kernel, virtual machines, sibling threads, and some trusted execution environments—by abusing speculative execution of gather instructions to expose stale vector register contents. Reported impacts include theft of passwords, encryption keys, SGX-protected data, and other memory-derived secrets, with shared and cloud environments highlighted as particularly exposed.

Intel said mitigation relies primarily on updated microcode that blocks transient results of gather instructions from being observed speculatively, while Microsoft directed Windows customers to obtain Intel platform updates from OEMs and noted the protection is enabled by default. VMware said hypervisor patches are generally not required if underlying firmware is updated, while Xen issued advisory XSA-435 and stable-tree fixes plus options such as restricting AVX for untrusted guests. Intel and downstream guidance warned that mitigation can carry noticeable performance costs—minimal for many workloads but up to 50% for gather-heavy applications—and added that newer Intel families such as Alder Lake, Raptor Lake, and Sapphire Rapids include protections and are not considered affected.

Share:
Downfall CPU flaw exposes data on affected Intel systems via Gather Data Sampling
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
May 8, 20262mo ago

Linux kernel documentation for GDS is published

The Linux kernel documentation published an administrative guide for Gather Data Sampling, providing platform-specific documentation for the vulnerability and its handling in Linux environments. This reflects ongoing ecosystem documentation after the original disclosure.

Jan 1, 20266mo ago

Microsoft publishes Windows guidance for CVE-2022-40982

Microsoft published KB5029778 with guidance for managing Gather Data Sampling on supported Windows systems running on affected Intel CPUs. It recommended Intel Platform Update 23.3 microcode from OEMs and stated the mitigation is enabled by default with no option to disable it.

May 12, 20242y ago

Intel publishes detailed technical mitigation guidance

Intel later published expanded technical documentation describing how the GDS microcode mitigation works, default enablement, MSR controls, SGX requirements, Key Locker exposure, and guidance for Linux, Windows, and virtualized environments. The documentation also reiterated that some gather-heavy workloads may see performance degradation of up to 50%.

Jan 29, 20242y ago

Intel publishes GDS threat analysis and risk guidance

Intel published a threat analysis for Gather Data Sampling assessing practical exploitability across deployment scenarios such as trusted systems, HPC, and multi-tenant cloud environments. The guidance said Intel was not aware of exploitation outside laboratory settings and advised administrators to balance threat exposure against potential performance impact when deciding whether to keep mitigations enabled.

Threat Analysis Guidance for Gather Data Sampling
Aug 10, 20233y ago

Performance impact of Downfall mitigations reported

Follow-up reporting highlighted that Intel's Downfall mitigations could significantly reduce performance, with some tests showing drops up to 39% and Intel warning certain workloads could see even higher impact. This clarified the operational tradeoffs of deploying the microcode fix.

Aug 8, 20233y ago

Xen publishes advisory and stable-branch fixes

Xen issued Security Advisory 435 for CVE-2022-40982, stating all Xen versions are affected on vulnerable Intel processors. Xen released fixes in stable versions 4.17.2, 4.16.5, 4.15.5, and 4.14.6, and also documented AVX-disabling mitigations.

VMware issues response and says hypervisor patches not required

VMware stated its hypervisors may be affected only when running on impacted Intel processors, but that VMware hypervisor patches were not required for remediation. Customers were directed to review Intel's advisory and obtain firmware updates from hardware vendors if needed.

Intel releases microcode mitigation for affected CPUs

At disclosure, Intel released microcode updates to mitigate CVE-2022-40982 on affected processors. Intel noted the mitigation is enabled by default and may impose substantial overhead on some gather-heavy workloads.

Downfall / GDS publicly disclosed by Intel and Google

Intel disclosed Gather Data Sampling on August 8, 2023, and Google researcher Daniel Moghimi publicly unveiled the Downfall attacks the same day. Public reporting described data leakage risks across processes, VMs, and SGX boundaries on affected Intel CPU generations.

Jul 8, 20233y ago

Intel publishes Gather Data Sampling advisory

Intel published advisory guidance for Gather Data Sampling, documenting the transient execution flaw and vendor guidance for affected processors. This marks Intel's public advisory for CVE-2022-40982.

Jan 1, 20233y ago

Downfall public site appears

A public Downfall project site was published, indicating coordinated public-facing material for the vulnerability. The exact event details are not provided in the reference beyond the site's existence.

Aug 1, 20224y ago

Google researcher reports Downfall to Intel

Daniel Moghimi reported the Gather Data Sampling / Downfall vulnerability to Intel in August 2022. The issue was later tracked as CVE-2022-40982.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
4 linked
LinuxWindowsGoogleXen
Organizations
3 linked
BleepingComputerIntelGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Downfall CPU flaw exposes data on affected Intel systems via Gather Data Sampling | Mallory