CVE-2022-23960
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In specific ARM processors, there is a possible side-channel information leak due to a hardware flaw. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
05 / REFERENCES
Further evidence
- https://android.googlesource.com/kernel/common/+/0777e59b105c05cb46ea877130e672223e87e0e8
- https://android.googlesource.com/kernel/common/+/124cc54b229a637e2ff7d70e5099ae4d6187e39f
- https://android.googlesource.com/kernel/common/+/150ecd86887b2571214a4d998eb8597434ebb476
- https://android.googlesource.com/kernel/common/+/15e43a2ac5e15c503c104831e9e2b6d5fc7d6131
- https://android.googlesource.com/kernel/common/+/16ddad71e36c65545bef2ab577adbc3e40fe4668
- https://android.googlesource.com/kernel/common/+/26e71fb73c4027d77a3212c8c9eff7e955e6ec45
- https://android.googlesource.com/kernel/common/+/5e6ae4e3cb2b045d69ac9cee1ae282d267283799
- https://android.googlesource.com/kernel/common/+/65b1e224b17749cad53443715dbf7f080338eac3
- https://android.googlesource.com/kernel/common/+/6d6256ca4bf5a77a7e3a99cf7c19f64eea82c1b0
- https://android.googlesource.com/kernel/common/+/873dbc2b8ecc2acf2388056bfced5bf6361a4c73
- https://android.googlesource.com/kernel/common/+/910e14e7d00119a382bb22c3c40f2fd7db3bc1e4
- https://android.googlesource.com/kernel/common/+/96468c6085fc87f1defb2b187bd778505723e1bc
- https://android.googlesource.com/kernel/common/+/9811efebb90ce7ea684a5599da729465abadcc22
- https://android.googlesource.com/kernel/common/+/9d4fc09b9e77f06a45a6762b116e867c3614a39d
- https://android.googlesource.com/kernel/common/+/a1736e3ccd78ceb797c3bc1b99b9114c2c00f450
- https://android.googlesource.com/kernel/common/+/a7cd57c87823bfe4c4eb88dfd045f242d6ddeeeb
- https://android.googlesource.com/kernel/common/+/b79237c4eadebf2d40ccb55734dd86fc6cbbc803
- https://android.googlesource.com/kernel/common/+/be161e5c6660b9c9ab1a2948a60a377e836b9685
- https://android.googlesource.com/kernel/common/+/c5aaa5f0d57ceb3d679f2c17bf555b29585d0f0e
- https://android.googlesource.com/kernel/common/+/cae54aa2645c769ba3263b1abd1e05cbd838f4a9
- https://android.googlesource.com/kernel/common/+/cf6a46ae183aaba1b08f183e3448f8756f8d68e1
- https://android.googlesource.com/kernel/common/+/d65dd058214689b75eaeb054647493511755db97
- https://android.googlesource.com/kernel/common/+/decde029b601e1a8b09d94f0864a1f518a140fb3
- https://android.googlesource.com/kernel/common/+/df38bfac784b0659f0c5eaa2b7ab7a11dfffb47e
- https://android.googlesource.com/kernel/common/+/e80db263bef5f31f0baffc5e41fcc179ae27fe22
- https://android.googlesource.com/kernel/common/+/ffb8d4139dbcc245ab7013d56c637cfa04c1d4cf
- https://source.android.com/security/bulletin/2022-12-01
- http://www.openwall.com/lists/oss-security/2022/03/18/2
- https://developer.arm.com/support/arm-security-updates
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
- https://www.debian.org/security/2022/dsa-5173