CVE-2022-23960
⚪ Do wiadomości
Błąd w procesorach Arm Cortex i Neoverse umożliwia wyciek poufnych danych przez spekulację pamięci podręcznej.
CVSS
5.6
EPSS
0.5%
Exploit
none
Vendor
arm
Opis źródłowy (NVD)
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2022-03-13 00:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:19 UTC |
Referencje
- http://www.openwall.com/lists/oss-security/2022/03/18/2 ([email protected]) [Mailing List, Patch, Third Party Advisory]
- https://developer.arm.com/support/arm-security-updates ([email protected]) [Vendor Advisory]
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability ([email protected]) [Mitigation, Patch, Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html ([email protected]) [Mailing List, Third Party Advisory]
- https://www.debian.org/security/2022/dsa-5173 ([email protected]) [Third Party Advisory]