CVE-2022-23960: Medium severity XEN Xen vulnerability

Published Mar 8, 2022
·
Updated

A new cache speculation vulnerability known as Branch History Injection (BHI) or Spectre-BHB was found. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's own hardware context. Once that occurs, speculation caused by mispredicted branches can be used to cause cache allocation, which can then be used to infer information that should not be accessible.

Other sources

A new cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, was found in hw. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. Once that occurs, speculation caused by the mispredicted branches can cause cache allocation. This issue leads to obtaining information that should not be accessible.

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

Affected Software

107 affected componentsFixes available
redhat/kernel<0:4.18.0-425.3.1.el8
0:4.18.0-425.3.1.el8
All of the following
XEN Xen
Any of the following
Arm Cortex-A57
Arm Cortex-a65
Arm Cortex-a65ae
Arm Cortex-a710
Arm Cortex-A72
Arm Cortex-A73
Arm Cortex-A75
Arm Cortex-a76
Arm Cortex-a76ae
Arm Cortex-A77
Arm Cortex-a78
Arm Cortex-a78ae
Arm Cortex-r7
Arm Cortex-r8
Arm Cortex-x1
Arm Cortex-x2
Arm Neoverse-e1
Arm Neoverse-v1
Arm Neoverse N1
Arm Neoverse N2
All of the following
Arm Cortex-r7 Firmware
Arm Cortex-r7
All of the following
Arm Cortex-r8 Firmware
Arm Cortex-r8
All of the following
Arm Cortex-a57 Firmware
Arm Cortex-A57
All of the following
Arm Cortex-a65 Firmware
Arm Cortex-a65
All of the following
Arm Cortex-a65ae Firmware
Arm Cortex-a65ae
All of the following
Arm Cortex-a710 Firmware
Arm Cortex-a710
All of the following
Arm Cortex-a72 Firmware
Arm Cortex-A72
All of the following
Arm Cortex-a73 Firmware
Arm Cortex-A73
All of the following
Arm Cortex-a75 Firmware
Arm Cortex-A75
All of the following
Arm Cortex-a76 Firmware
Arm Cortex-a76
All of the following
Arm Cortex-a76ae Firmware
Arm Cortex-a76ae
All of the following
Arm Cortex-a77 Firmware
Arm Cortex-A77
All of the following
Arm Cortex-a78 Firmware
Arm Cortex-a78
All of the following
Arm Cortex-a78ae Firmware
Arm Cortex-a78ae
All of the following
Arm Cortex-x1 Firmware
Arm Cortex-x1
All of the following
Arm Cortex-x2 Firmware
Arm Cortex-x2
All of the following
Arm Neoverse-e1 Firmware
Arm Neoverse-e1
All of the following
Arm Neoverse-v1 Firmware
Arm Neoverse-v1
All of the following
Arm Neoverse N1 Firmware
Arm Neoverse N1
All of the following
Arm Neoverse N2 Firmware
Arm Neoverse N2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
XEN Xen
Arm Cortex-A57
Arm Cortex-a65
Arm Cortex-a65ae
Arm Cortex-a710
Arm Cortex-A72
Arm Cortex-A73
Arm Cortex-A75
Arm Cortex-a76
Arm Cortex-a76ae
Arm Cortex-A77
Arm Cortex-a78
Arm Cortex-a78ae
Arm Cortex-r7
Arm Cortex-r8
Arm Cortex-x1
Arm Cortex-x2
Arm Neoverse-e1
Arm Neoverse-v1
Arm Neoverse N1
Arm Neoverse N2
Arm Cortex-r7 Firmware
Arm Cortex-r8 Firmware
Arm Cortex-a57 Firmware
Arm Cortex-a65 Firmware
Arm Cortex-a65ae Firmware
Arm Cortex-a710 Firmware
Arm Cortex-a72 Firmware
Arm Cortex-a73 Firmware
Arm Cortex-a75 Firmware
Arm Cortex-a76 Firmware
Arm Cortex-a76ae Firmware
Arm Cortex-a77 Firmware
Arm Cortex-a78 Firmware
Arm Cortex-a78ae Firmware
Arm Cortex-x1 Firmware
Arm Cortex-x2 Firmware
Arm Neoverse-e1 Firmware
Arm Neoverse-v1 Firmware
Arm Neoverse N1 Firmware
Arm Neoverse N2 Firmware
Google Android
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Remediation

Information

Disabling unprivileged eBPF effectively mitigates the known attack vectors for exploiting intra-mode branch injections attacks. The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. For the Red Hat Enterprise Linux 7, the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw.

Mitigation

To mitigate the primary known attack vector, disable unprivileged eBPF: $ sudo sysctl kernel.unprivileged_bpf_disabled=1 or $ sudo sysctl kernel.unprivileged_bpf_disabled=2

Event History

Mar 8, 2022
CVE Published
12:00 AM
Mar 9, 2022
Data Sourced
via Red Hat·01:26 PM
DescriptionSeverityAffected Software
Mar 12, 2022
CVE Published
via MITRE·11:57 PM
Data Sourced
via MITRE·11:57 PM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:07 AM
Description
May 2, 2025
Data Sourced
via Ubuntu·04:19 AM
RemedyDescriptionSeverityAffected Software
May 6, 2025
Data Sourced
via Debian·04:20 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-23960?

CVE-2022-23960 is classified as a high-severity vulnerability due to its potential impact on sensitive data.

2

How do I fix CVE-2022-23960?

To mitigate CVE-2022-23960, ensure that your system is updated to the latest kernel version that includes patches addressing the vulnerability.

3

Which systems are affected by CVE-2022-23960?

CVE-2022-23960 affects multiple systems, including versions of Red Hat kernel, Google Android, and various Arm Cortex processors.

4

What type of vulnerability is CVE-2022-23960?

CVE-2022-23960 is a cache speculation vulnerability categorized under the Spectre family, which utilizes branch history manipulation.

5

Is CVE-2022-23960 a confirmed exploitation?

As of now, there are no confirmed cases of exploitation specifically targeting CVE-2022-23960 in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203