CVE-2022-23960Linux vulnerability

19 documents12 sources
Severity
5.6MEDIUMNVD
OSV6.5
EPSS
0.2%
top 58.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateFeb 14

Description

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 1.1 | Impact: 4.0

Affected Packages6 packages

debiandebian/linux< linux 5.16.14-1 (bookworm)
Debianlinux/linux_kernel< 5.10.106-1+3
Ubuntulinux/linux_kernel< 5.4.0-104.118
Palo Altopaloalto/pan-os

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

7
OSV
CVE-2022-23960: In specific ARM processors, there is a possible side-channel information leak due to a hardware flaw2022-12-01
OSV
linux-intel-5.13 vulnerabilities2022-04-01
GHSA
GHSA-m7j2-567h-fvrw: Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB2022-03-14
OSV
CVE-2022-23960: Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB2022-03-13
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-azure-fde, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-2022-03-09

📋Vendor Advisories

8
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Android
CVE-2022-23960: Kernel2022-12-01
Microsoft
Arm: CVE-2022-23960 Cache Speculation Restriction Vulnerability2022-09-13
Ubuntu
Linux kernel (Intel IOTG) vulnerabilities2022-04-01
Ubuntu
Linux kernel vulnerabilities2022-03-09

🕵️Threat Intelligence

3
Tenable
Microsoft’s September 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-37969)2022-09-13
Qualys
September 2022 Patch Tuesday | Microsoft Releases 63 Vulnerabilities With 5 Critical, Plus 16 Microsoft Edge (Chromium-Based); Adobe Releases 7 Advisories, 63 Vulnerabilities With 35 Critical.2022-09-13
Qualys
September 2022 Patch Tuesday | Microsoft Releases 63 Vulnerabilities With 5 Critical, Plus 16 Microsoft Edge (Chromium-Based); Adobe Releases 7 Advisories, 63 Vulnerabilities With 35 Critical. | Qualy2022-09-13