CVE-2020-13844Observable Discrepancy in Leap

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 66.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 24

Description

Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDopensuse/leap15.1, 15.2+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-jwjh-w2wp-2gvv: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of infor2022-05-24
OSV
CVE-2020-13844: In exception handling functions of multiple files, there is a possible info leak due to side channel information disclosure2022-04-01
OSV
CVE-2020-13844: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of infor2020-06-08
CVEList
CVE-2020-13844: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of infor2020-06-08

📋Vendor Advisories

1
Red Hat
kernel: ARM straight-line speculation vulnerability2020-06-07

💬Community

2
Bugzilla
CVE-2020-13844 kernel: ARM straight-line speculation vulnerability [fedora-all]2020-06-18
Bugzilla
CVE-2020-13844 kernel: ARM straight-line speculation vulnerability2020-06-18
CVE-2020-13844 — Observable Discrepancy in Leap | cvebase