CVE-2022-23960

Aliases:UBUNTU-CVE-2022-23960DEBIAN-CVE-2022-23960ALPINE-CVE-2022-23960
Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 12 Mar 2022, 23:57
Last modified:03 Aug 2024, 03:59

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.6 MEDIUM
v3.1 (nvd)
EPSS Score
0.5% LOW
0% probability +0.32%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Mar 2022, 23:57
Published
Vulnerability first disclosed
03 Aug 2024, 03:59
Last Modified
Vulnerability information updated

Description

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.50% Percentile: 42%

Affected Systems

  • alpinexen

    < 4.13.4-r3

  • armcortex-a57_firmware

    na

  • armcortex-a65_firmware

    na

  • armcortex-a65ae_firmware

    na

  • armcortex-a710

    na

  • armcortex-a72_firmware

    na

  • armcortex-a73_firmware

    na

  • armcortex-a75_firmware

    na

  • armcortex-a76

    na

  • armcortex-a76ae

    na

  • armcortex-a77

    na

  • armcortex-a78

    na

  • armcortex-a78ae

    na

  • armcortex-r7_firmware

    na

  • armcortex-r8_firmware

    na

  • armcortex-x1

    na

  • armcortex-x2

    na

  • armneoverse n1

    na

  • armneoverse n2

    na

  • armneoverse-e1_firmware

    na

  • armneoverse-v1_firmware

    na

  • debianlinux

    < 5.10.106-1 | < 5.16.14-1 | < 5.16.14-1 | < 5.16.14-1

  • ubuntulinux

    all | < 4.15.0-184.194 | < 5.4.0-117.132

  • ubuntulinux-aws

    all | < 4.15.0-1133.143 | < 5.4.0-1078.84

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    < 5.13.0-1017.19~20.04.1

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1078.84~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-fips

    < 4.15.0-2072.76 | all | < 5.4.0-1078.84+fips1

  • ubuntulinux-aws-hwe

    < 4.15.0-1133.143~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1142.156~14.04.1 | < 4.15.0-1142.156~16.04.1 | all | < 5.4.0-1083.87

  • ubuntulinux-azure-4.15

    < 4.15.0-1142.156

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    < 5.13.0-1017.19~20.04.1

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1083.87~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fips

    < 4.15.0-2053.58 | all | < 5.4.0-1083.87+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1040.44

  • ubuntulinux-dell300x

    < 4.15.0-1047.52

  • ubuntulinux-fips

    all | < 4.15.0-1090.100 | < 5.4.0-1054.61

  • ubuntulinux-gcp

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2037.41 | all | < 5.4.0-1078.84+fips1

  • ubuntulinux-hwe

    < 4.15.0-184.194~16.04.1 | all

Showing first 50 affected entries in server-rendered view.

References (16)