CVE-2022-23960
Last modified
CVE-2022-23960 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | All versions |
| Arm | Cortex-R7 Firmware | All versions |
| Arm | Cortex-R8 Firmware | All versions |
| Arm | Cortex-A57 Firmware | All versions |
| Arm | Cortex-A65 Firmware | All versions |
| Arm | Cortex-A65ae Firmware | All versions |
| Arm | Cortex-A710 Firmware | All versions |
| Arm | Cortex-A72 Firmware | All versions |
| Arm | Cortex-A73 Firmware | All versions |
| Arm | Cortex-A75 Firmware | All versions |
| Arm | Cortex-A76 Firmware | All versions |
| Arm | Cortex-A76ae Firmware | All versions |
| Arm | Cortex-A77 Firmware | All versions |
| Arm | Cortex-A78 Firmware | All versions |
| Arm | Cortex-A78ae Firmware | All versions |
| Arm | Cortex-X1 Firmware | All versions |
| Arm | Cortex-X2 Firmware | All versions |
| Arm | Neoverse-E1 Firmware | All versions |
| Arm | Neoverse-V1 Firmware | All versions |
| Arm | Neoverse N1 Firmware | All versions |
| Arm | Neoverse N2 Firmware | All versions |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- https://www.openwall.com/lists/oss-security/2022/03/18/2Mailing List, Patch, Third Party Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityMitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5173Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/18/2Mailing List, Patch, Third Party Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityMitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5173Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23960?
How severe is CVE-2022-23960?
How do I fix CVE-2022-23960?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23955Potential vulnerabilities have been identified in the BIOS f…5.5
- CVE-2022-23956Potential vulnerabilities have been identified in the BIOS f…5.5
- CVE-2022-23957Potential vulnerabilities have been identified in the BIOS f…5.5
- CVE-2022-23958Potential vulnerabilities have been identified in the BIOS f…5.5
- CVE-2022-23959In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish …9.1
- CVE-2022-2396A vulnerability classified as problematic was found in Sourc…5.4
- CVE-2022-23961In Thruk Monitoring through 2.46.3, the login field of the l…6.1
- CVE-2022-23967Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-23968Xerox VersaLink devices on specific versions of firmware bef…7.5
- CVE-2022-23970ASUS RT-AX56U’s update_json function has a path traversal vu…8.1
- CVE-2022-23971ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vu…8.1
- CVE-2022-23972ASUS RT-AX56U’s SQL handling function has an SQL injection v…8.8
Are you affected by CVE-2022-23960?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
