cbcvebase.
CVE-2022-23960
published 2022-03-13

CVE-2022-23960: Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared…

PriorityP425medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.50%
40.0th percentile
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.16.14-1 (bookworm)linux 5.16.14-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 5.10.106-15.10.106-1
linuxlinux_kernel>= 0 < 5.16.14-15.16.14-1
linuxlinux_kernel>= 0 < 5.16.14-15.16.14-1
linuxlinux_kernel>= 0 < 5.16.14-15.16.14-1
linuxlinux_kernel>= 0 < 5.4.0-104.1185.4.0-104.118
msrcwindows_11_version_21h2_for_arm64-based_systems
paloaltopan-os

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.6MEDIUM
vendor_msrc5.6HIGH
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.