CVE-2022-0002: Medium severity intel atom c3308 firmware vulnerability
A flaw was found in hw. The Intra-mode BTI refers to a variant of Branch Target Injection aka SpectreV2 (BTI) where an indirect branch speculates to an aliased predictor entry for a different indirect branch in the same predictor mode, and a disclosure gadget at the predicted target transiently executes. These predictor entries may contain targets corresponding to the targets of an indirect near jump, indirect near call, and near return instructions, even if these branches were only transiently executed. The managed runtimes provide an attacker with the means to create the aliasing required for intra-mode BTI attacks.
Other sources
Intra-mode BTI refers to a variant of BTI (Branch Target Injection aka SpectreV2) where an indirect branch speculates to an aliased predictor entry for a different indirect branch in the same predictor mode , and a disclosure gadget at the predicted target will transiently execute. Such predictor entries may contain targets corresponding to the targets of indirect near jump, indirect near call and/or near return instructions, even if these branches were only transiently executed. Managed runtimes can provide an attacker with the means to create the aliasing required for intra-mode BTI attacks.
— Red Hat
Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Affected Software
Remediation
Information
Patch Available
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-0002?
CVE-2022-0002 has been assigned a high severity rating due to its potential for exploiting branch target injection vulnerabilities.
How do I fix CVE-2022-0002?
To mitigate CVE-2022-0002, update to the recommended Linux kernel versions, specifically kernel-rt version 0:4.18.0-372.9.1.rt7.166.el8 or kernel version 0:4.18.0-372.9.1.el8.
What are the affected systems for CVE-2022-0002?
CVE-2022-0002 affects various Intel Atom, Celeron, and Core processors, as well as specific versions of the Linux kernel.
Is there a workaround for CVE-2022-0002?
While the best resolution is to apply the kernel updates, minimizing exposure through robust firewall configurations can serve as a temporary workaround.
Are there any public exploits for CVE-2022-0002?
As of now, there are no known public exploits specifically targeting CVE-2022-0002.