CVE-2020-10767
Last modified
CVE-2020-10767 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configuration is active. The highest threat from this vulnerability is to confidentiality.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.8.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10767Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10767Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10767?
How severe is CVE-2020-10767?
How do I fix CVE-2020-10767?
Are you affected by CVE-2020-10767?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
