CVE-2022-23824
published 2022-11-09CVE-2022-23824: IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.59%
43.9th percentile
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_processors | — | — |
| debian | xen | < xen 4.16.2+90-g0d39a6d1ae-1 (bookworm) | xen 4.16.2+90-g0d39a6d1ae-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| xen | xen | >= 0 < 4.14.5+94-ge49571868d-1 | 4.14.5+94-ge49571868d-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_redhat5.6MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hhhj-6x4j-w995: IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure
ghsa_unreviewed·2022-11-10
CVE-2022-23824 [MEDIUM] GHSA-hhhj-6x4j-w995: IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
OSV
CVE-2022-23824: IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure
osv·2022-11-09·CVSS 5.5
CVE-2022-23824 [MEDIUM] CVE-2022-23824: IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
Microsoft
AMD: CVE-2022-23824 IBPB and Return Address Predictor Interactions
vendor_msrc·2022-11-08·CVSS 5.5
CVE-2022-23824 [MEDIUM] AMD: CVE-2022-23824 IBPB and Return Address Predictor Interactions
AMD: CVE-2022-23824 IBPB and Return Address Predictor Interactions
FAQ: Are any additional steps required to protect my system after installing the November Windows updates?
Customers who allow untrusted users to execute arbitrary code might wish to implement some extra security features within their systems. These features protect against the intra-process disclosure vectors that this speculative execution vulnerability describes. See the following for more information.
Microsoft Windows client customers: See Microsoft Knowledge Base Article 4073119.
Microsoft Windows Server/Azure Stack HCI customers: See Microsoft Knowledge Base Article 4072698 for additional information, including workarounds.
Microsoft Azure has taken steps to address the security vulnerabilities at the hypervisor l
Red Hat
hw: cpu: AMD: IBPB and Return Address Predictor Interactions
vendor_redhat·2022-07-12·CVSS 5.6
CVE-2022-23824 [MEDIUM] CWE-1037 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
hw: cpu: AMD: IBPB and Return Address Predictor Interactions
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
A flaw was found in hw. The AMD CPUs can be attacked similar to the previously known Spectre Variant 2 (CVE-2017-5715). This issue affects AMD CPUs where the OS relies on IBPB to flush the return address predictor. As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks.
Mitigation: Please see the vulnerability response article for the full list of updates available and a detailed discussion of this issue, which compares the existing mitigation for CVE-2022-23816
Debian
CVE-2022-23824: xen - IBPB may not prevent return branch predictions from being specified by pre-IBPB ...
vendor_debian·2022·CVSS 5.5
CVE-2022-23824 [MEDIUM] CVE-2022-23824: xen - IBPB may not prevent return branch predictions from being specified by pre-IBPB ...
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
Scope: local
bookworm: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
bullseye: resolved (fixed in 4.14.5+94-ge49571868d-1)
forky: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
sid: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
trixie: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
blogs_bleepingcomputer·2024-10-18·CVSS 5.5
[MEDIUM] Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
## Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
## Bill Toulas
Speculative execution is a performance optimization feature on modern CPUs that executes instructions before knowing if they are needed by future tasks, thus speeding up the process when the prediction is correct. Instructions executed based on the misprediction are called transient and are squashed.
This mechanism has been a source of side-channel risks, such as Spectre , because the speculation process calls sensitive data that could be retrieved from the CPU cache.
## New Spectre-like attacks
ETH Zurich researchers Johannes Wikner and Kaveh Razavi explain that despite the multi-year mitigation effort to contain Spectre-like attacks, there have been numerous variants that bypass existing defenses.
Bugzilla
CVE-2022-23824 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
bugzilla·2022-08-17·CVSS 5.6
CVE-2022-23824 [MEDIUM] CVE-2022-23824 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
CVE-2022-23824 hw: cpu: AMD: IBPB and Return Address Predictor Interactions
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
This issue (CVE-2022-23824 or AMD-SN-1040) related to CVE-2017-5715 previously known as Spectre Variant 2. As part of our efforts to continue improving security features, AMD has investigated issues related to CVE-2017-5715 in the recent months. Previously notified of one of the potential issues related to CVE-2017-5715 (in AMD-SN-1036). In some situations, IBPB may fail to prevent return branch predictions from being specified by pre-IBPB branch targets leading to potential information disclosure.
Reference:
https://www.amd.com/en/corporate/product-security/bulletin/amd-s
http://www.openwall.com/lists/oss-security/2022/11/10/2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTQMPJC5N6XJYQ232OZFLK47HVZNRBY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/https://security.gentoo.org/glsa/202402-07https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1040https://www.debian.org/security/2023/dsa-5378http://www.openwall.com/lists/oss-security/2022/11/10/2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTQMPJC5N6XJYQ232OZFLK47HVZNRBY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/https://security.gentoo.org/glsa/202402-07https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1040https://www.debian.org/security/2023/dsa-5378
2022-11-09
Published