CVE-2022-25368

MEDIUMCVSS 4.7/10EPSS 0.29%

Last modified

CVE-2022-25368 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.

Description

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

Metrics

CVSS 3.1
4.7/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.29%

20.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
AmperecomputingAmpere Altra Max FirmwareAll versions
AmperecomputingAmpere Altra FirmwareAll versions
ArmNeoverse-E1 FirmwareAll versions
ArmNeoverse-V1 FirmwareAll versions
ArmCortex-A57 FirmwareAll versions
ArmCortex-A65 FirmwareAll versions
ArmCortex-A65ae FirmwareAll versions
ArmCortex-A72 FirmwareAll versions
ArmCortex-A73 FirmwareAll versions
ArmCortex-A75 FirmwareAll versions
ArmCortex-A76 FirmwareAll versions
ArmCortex-A76ae FirmwareAll versions
ArmCortex-A77 FirmwareAll versions
ArmCortex-A78 FirmwareAll versions
ArmCortex-A78ae FirmwareAll versions
ArmCortex-A78c FirmwareAll versions
ArmCortex-X1 FirmwareAll versions
ArmCortex-X2 FirmwareAll versions
ArmCortex-A710 FirmwareAll versions
ArmCortex-A15 FirmwareAll versions
ArmNeoverse N1 FirmwareAll versions
ArmNeoverse N2 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-25368?
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.
How severe is CVE-2022-25368?
CVE-2022-25368 has a CVSS score of 4.7/10 (MEDIUM severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2022-25368?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-25368?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST