VulnerabilityModified
CVE-2022-23960
An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches.
MEDIUM 5.6EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Affected
- xen/xen · arm/cortex-r7 firmware · arm/cortex-r8 firmware · arm/cortex-a57 firmware · arm/cortex-a65 firmware · arm/cortex-a65ae firmware · arm/cortex-a710 firmware · arm/cortex-a72 firmware · arm/cortex-a73 firmware · arm/cortex-a75 firmware · arm/cortex-a76 firmware · arm/cortex-a76ae firmware · arm/cortex-a77 firmware · arm/cortex-a78 firmware · arm/cortex-a78ae firmware · arm/cortex-x1 firmware · arm/cortex-x2 firmware · arm/neoverse-e1 firmware · arm/neoverse-v1 firmware · arm/neoverse n1 firmware · +2 more
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2022/03/18/2Mailing List, Patch, Third Party Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityMitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5173Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/03/18/2Mailing List, Patch, Third Party Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityMitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5173Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.