CVE-2023-3006
Last modified
CVE-2023-3006 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. Once that occurs, speculation caused by the mispredicted branches can cause cache allocation. This issue leads to obtaining information that should not be accessible.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | 6.1 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3006?
How severe is CVE-2023-3006?
How do I fix CVE-2023-3006?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30053TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Comm…9.8
- CVE-2023-30054TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injecti…9.8
- CVE-2023-30056A session takeover vulnerability exists in FICO Origination …7.5
- CVE-2023-30057Multiple stored cross-site scripting (XSS) vulnerabilities i…5.4
- CVE-2023-30058novel-plus 3.6.2 is vulnerable to SQL Injection.9.8
- CVE-2023-30059An insecure direct object reference in MK-Auth 23.01K4.9 all…5.4
- CVE-2023-30061D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass…7.5
- CVE-2023-30063D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication by…7.5
- CVE-2023-30065MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b…8.8
- CVE-2023-3007A vulnerability was found in ningzichun Student Management S…9.8
- CVE-2023-30076Sourcecodester Judging Management System v1.0 is vulnerable …9.8
- CVE-2023-30077Judging Management System v1.0 by oretnom23 was discovered t…9.8
Are you affected by CVE-2023-3006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
