CVE-2022-23960

MEDIUMCVSS 5.6/10EPSS 0.50%

Last modified

CVE-2022-23960 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. EPSS estimates a 0.50% chance of exploitation in the next 30 days.

Description

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

Metrics

CVSS 3.1
5.6/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Probability
0.50%

38.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
XenXenAll versions
ArmCortex-R7 FirmwareAll versions
ArmCortex-R8 FirmwareAll versions
ArmCortex-A57 FirmwareAll versions
ArmCortex-A65 FirmwareAll versions
ArmCortex-A65ae FirmwareAll versions
ArmCortex-A710 FirmwareAll versions
ArmCortex-A72 FirmwareAll versions
ArmCortex-A73 FirmwareAll versions
ArmCortex-A75 FirmwareAll versions
ArmCortex-A76 FirmwareAll versions
ArmCortex-A76ae FirmwareAll versions
ArmCortex-A77 FirmwareAll versions
ArmCortex-A78 FirmwareAll versions
ArmCortex-A78ae FirmwareAll versions
ArmCortex-X1 FirmwareAll versions
ArmCortex-X2 FirmwareAll versions
ArmNeoverse-E1 FirmwareAll versions
ArmNeoverse-V1 FirmwareAll versions
ArmNeoverse N1 FirmwareAll versions
ArmNeoverse N2 FirmwareAll versions
DebianDebian Linux9.0
DebianDebian Linux10.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-23960?
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
How severe is CVE-2022-23960?
CVE-2022-23960 has a CVSS score of 5.6/10 (MEDIUM severity). The EPSS model estimates a 0.50% probability of exploitation in the next 30 days.
How do I fix CVE-2022-23960?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-23960?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST