CVE-2020-13844: Medium severity Arm Cortex-a32 Firmware vulnerability
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13844?
CVE-2020-13844 refers to Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
What software is affected by CVE-2020-13844?
The Arm Cortex-a32 Firmware, Arm Cortex-a35 Firmware, Arm Cortex-a53 Firmware, Arm Cortex-a57 Firmware, Arm Cortex-a72 Firmware, Arm Cortex-a73 Firmware, Arm Cortex-a34, openSUSE Leap 15.1, and openSUSE Leap 15.2 are affected by CVE-2020-13844.
What is the severity of CVE-2020-13844?
The severity of CVE-2020-13844 is medium with a CVSS score of 5.5.
Where can I find more information about CVE-2020-13844?
You can find more information about CVE-2020-13844 at the following references: [http://lists.llvm.org/pipermail/llvm-dev/2020-June/142109.html](http://lists.llvm.org/pipermail/llvm-dev/2020-June/142109.html), [http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00039.html](http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00039.html), [http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00040.html](http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00040.html).
What is the CWE of CVE-2020-13844?
CVE-2020-13844 is associated with CWE-203.