CVE-2022-23960: Medium severity XEN Xen vulnerability
A new cache speculation vulnerability known as Branch History Injection (BHI) or Spectre-BHB was found. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's own hardware context. Once that occurs, speculation caused by mispredicted branches can be used to cause cache allocation, which can then be used to infer information that should not be accessible.
Other sources
A new cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, was found in hw. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. Once that occurs, speculation caused by the mispredicted branches can cause cache allocation. This issue leads to obtaining information that should not be accessible.
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
Affected Software
Remediation
Information
Patch Available
Mitigation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23960?
CVE-2022-23960 is classified as a high-severity vulnerability due to its potential impact on sensitive data.
How do I fix CVE-2022-23960?
To mitigate CVE-2022-23960, ensure that your system is updated to the latest kernel version that includes patches addressing the vulnerability.
Which systems are affected by CVE-2022-23960?
CVE-2022-23960 affects multiple systems, including versions of Red Hat kernel, Google Android, and various Arm Cortex processors.
What type of vulnerability is CVE-2022-23960?
CVE-2022-23960 is a cache speculation vulnerability categorized under the Spectre family, which utilizes branch history manipulation.
Is CVE-2022-23960 a confirmed exploitation?
As of now, there are no confirmed cases of exploitation specifically targeting CVE-2022-23960 in the wild.