CVE-2020-13844 — Observable Discrepancy in Leap
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 66.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 24
Description
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages1 packages
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-jwjh-w2wp-2gvv: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of infor↗2022-05-24
OSV▶
CVE-2020-13844: In exception handling functions of multiple files, there is a possible info leak due to side channel information disclosure↗2022-04-01
OSV▶
CVE-2020-13844: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of infor↗2020-06-08
CVEList▶
CVE-2020-13844: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of infor↗2020-06-08