First published: Fri Feb 03 2023(Updated: )
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the victim vulnerable to values already injected on the BTB, prior to the prctl syscall. The patch that added the support for the conditional mitigation via prctl (ib_prctl_set) dates back to the kernel 4.9.176. We recommend upgrading past commit a664ec9158eeddd75121d39c9a0758016097fa96
Credit: cve-coordination@google.com cve-coordination@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.16.68<3.17 | |
Linux Linux kernel | >=4.4.180<4.5 | |
Linux Linux kernel | >=4.9.176<4.10 | |
Linux Linux kernel | >=4.14.86<4.14.303 | |
Linux Linux kernel | >=4.19.7<4.19.270 | |
Linux Linux kernel | >=4.20<5.4.229 | |
Linux Linux kernel | >=5.5.0<5.10.163 | |
Linux Linux kernel | >=5.11<5.15.87 | |
Linux Linux kernel | >=5.16<6.0.19 | |
Linux Linux kernel | >=6.1<6.1.5 | |
Debian Debian Linux | =10.0 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
All of | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
debian/linux | 5.10.218-1 5.10.221-1 6.1.94-1 6.1.99-1 6.9.10-1 6.9.12-1 | |
ubuntu/linux | <4.15.0-208.220 | 4.15.0-208.220 |
ubuntu/linux | <5.4.0-144.161 | 5.4.0-144.161 |
ubuntu/linux | <5.15.0-69.76 | 5.15.0-69.76 |
ubuntu/linux | <5.19.0-38.39 | 5.19.0-38.39 |
ubuntu/linux | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux | <4.4.0-237.271 | 4.4.0-237.271 |
ubuntu/linux-aws | <4.15.0-1153.166 | 4.15.0-1153.166 |
ubuntu/linux-aws | <5.4.0-1097.105 | 5.4.0-1097.105 |
ubuntu/linux-aws | <5.15.0-1033.37 | 5.15.0-1033.37 |
ubuntu/linux-aws | <5.19.0-1022.23 | 5.19.0-1022.23 |
ubuntu/linux-aws | <6.2.0-1002.2 | 6.2.0-1002.2 |
ubuntu/linux-aws | <4.4.0-1116.122 | 4.4.0-1116.122 |
ubuntu/linux-aws | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws | <4.4.0-1154.169 | 4.4.0-1154.169 |
ubuntu/linux-aws-5.0 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws-5.15 | <5.15.0-1033.37~20.04.1 | 5.15.0-1033.37~20.04.1 |
ubuntu/linux-aws-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws-5.4 | <5.4.0-1097.105~18.04.1 | 5.4.0-1097.105~18.04.1 |
ubuntu/linux-aws-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws-fips | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws-hwe | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-aws-hwe | <4.15.0-1153.166~16.04.1 | 4.15.0-1153.166~16.04.1 |
ubuntu/linux-azure | <5.4.0-1104.110 | 5.4.0-1104.110 |
ubuntu/linux-azure | <5.15.0-1035.42 | 5.15.0-1035.42 |
ubuntu/linux-azure | <5.19.0-1022.23 | 5.19.0-1022.23 |
ubuntu/linux-azure | <6.2.0-1002.2 | 6.2.0-1002.2 |
ubuntu/linux-azure | <4.15.0-1162.177~14.04.1 | 4.15.0-1162.177~14.04.1 |
ubuntu/linux-azure | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure | <4.15.0-1162.177~16.04.1 | 4.15.0-1162.177~16.04.1 |
ubuntu/linux-azure-4.15 | <4.15.0-1162.177 | 4.15.0-1162.177 |
ubuntu/linux-azure-4.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-5.15 | <5.15.0-1035.42~20.04.1 | 5.15.0-1035.42~20.04.1 |
ubuntu/linux-azure-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-5.19 | <5.19.0-1022.23~22.04.1 | 5.19.0-1022.23~22.04.1 |
ubuntu/linux-azure-5.4 | <5.4.0-1104.110~18.04.1 | 5.4.0-1104.110~18.04.1 |
ubuntu/linux-azure-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-edge | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-fde | <5.4.0-1104.110 | 5.4.0-1104.110 |
ubuntu/linux-azure-fde | <5.15.0-1035.42.1 | 5.15.0-1035.42.1 |
ubuntu/linux-azure-fde | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-fde-5.15 | <5.15.0-1035.42~20.04.1.1 | 5.15.0-1035.42~20.04.1.1 |
ubuntu/linux-azure-fde-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-azure-fips | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-bluefield | <5.4.0-1059.65 | 5.4.0-1059.65 |
ubuntu/linux-bluefield | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-dell300x | <4.15.0-1062.67 | 4.15.0-1062.67 |
ubuntu/linux-dell300x | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-fips | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gcp | <5.4.0-1101.110 | 5.4.0-1101.110 |
ubuntu/linux-gcp | <5.15.0-1031.38 | 5.15.0-1031.38 |
ubuntu/linux-gcp | <5.19.0-1019.21 | 5.19.0-1019.21 |
ubuntu/linux-gcp | <6.2.0-1004.4 | 6.2.0-1004.4 |
ubuntu/linux-gcp | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gcp | <4.15.0-1147.163~16.04.1 | 4.15.0-1147.163~16.04.1 |
ubuntu/linux-gcp-4.15 | <4.15.0-1147.163 | 4.15.0-1147.163 |
ubuntu/linux-gcp-4.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gcp-5.15 | <5.15.0-1031.38~20.04.1 | 5.15.0-1031.38~20.04.1 |
ubuntu/linux-gcp-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gcp-5.4 | <5.4.0-1101.110~18.04.1 | 5.4.0-1101.110~18.04.1 |
ubuntu/linux-gcp-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gcp-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gcp-fips | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gke | <5.4.0-1095.102 | 5.4.0-1095.102 |
ubuntu/linux-gke | <5.15.0-1030.35 | 5.15.0-1030.35 |
ubuntu/linux-gke | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gke-4.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gke-5.0 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gke-5.15 | <5.15.0-1029.34~20.04.1 | 5.15.0-1029.34~20.04.1 |
ubuntu/linux-gke-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gke-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gkeop | <5.4.0-1065.69 | 5.4.0-1065.69 |
ubuntu/linux-gkeop | <5.15.0-1017.22 | 5.15.0-1017.22 |
ubuntu/linux-gkeop | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gkeop-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-gkeop-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-hwe | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-hwe | <4.15.0-208.219~16.04.1 | 4.15.0-208.219~16.04.1 |
ubuntu/linux-hwe-5.15 | <5.15.0-69.76~20.04.1 | 5.15.0-69.76~20.04.1 |
ubuntu/linux-hwe-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-hwe-5.19 | <5.19.0-38.39~22.04.1 | 5.19.0-38.39~22.04.1 |
ubuntu/linux-hwe-5.4 | <5.4.0-144.161~18.04.1 | 5.4.0-144.161~18.04.1 |
ubuntu/linux-hwe-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-hwe-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-hwe-edge | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-ibm | <5.4.0-1045.50 | 5.4.0-1045.50 |
ubuntu/linux-ibm | <5.15.0-1027.30 | 5.15.0-1027.30 |
ubuntu/linux-ibm | <5.19.0-1019.21 | 5.19.0-1019.21 |
ubuntu/linux-ibm | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-ibm-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-ibm-5.4 | <5.4.0-1045.50~18.04.1 | 5.4.0-1045.50~18.04.1 |
ubuntu/linux-ibm-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-intel | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-intel-5.13 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-intel-iotg | <5.15.0-1027.32 | 5.15.0-1027.32 |
ubuntu/linux-intel-iotg | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-intel-iotg-5.15 | <5.15.0-1027.32~20.04.1 | 5.15.0-1027.32~20.04.1 |
ubuntu/linux-intel-iotg-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-iot | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-kvm | <4.15.0-1137.142 | 4.15.0-1137.142 |
ubuntu/linux-kvm | <5.4.0-1087.93 | 5.4.0-1087.93 |
ubuntu/linux-kvm | <5.15.0-1030.35 | 5.15.0-1030.35 |
ubuntu/linux-kvm | <5.19.0-1020.21 | 5.19.0-1020.21 |
ubuntu/linux-kvm | <6.2.0-1002.2 | 6.2.0-1002.2 |
ubuntu/linux-kvm | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-kvm | <4.4.0-1117.127 | 4.4.0-1117.127 |
ubuntu/linux-laptop | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-lowlatency | <5.15.0-69.76 | 5.15.0-69.76 |
ubuntu/linux-lowlatency | <5.19.0-1021.22 | 5.19.0-1021.22 |
ubuntu/linux-lowlatency | <6.2.0-1002.2 | 6.2.0-1002.2 |
ubuntu/linux-lowlatency | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-lowlatency-hwe-5.15 | <5.15.0-69.76~20.04.1 | 5.15.0-69.76~20.04.1 |
ubuntu/linux-lowlatency-hwe-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-lowlatency-hwe-5.19 | <5.19.0-1021.22~22.04.1 | 5.19.0-1021.22~22.04.1 |
ubuntu/linux-lowlatency-hwe-5.19 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-lowlatency-hwe-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-lts-xenial | <4.4.0-237.271~14.04.1 | 4.4.0-237.271~14.04.1 |
ubuntu/linux-lts-xenial | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-nvidia | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-nvidia-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-nvidia-6.8 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-nvidia-lowlatency | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-5.10 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-5.14 | <5.14.0-1058.66 | 5.14.0-1058.66 |
ubuntu/linux-oem-5.14 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-5.17 | <5.17.0-1028.29 | 5.17.0-1028.29 |
ubuntu/linux-oem-5.17 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-5.6 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-6.0 | <6.0.0-1012.12 | 6.0.0-1012.12 |
ubuntu/linux-oem-6.0 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-6.1 | <6.1.0-1007.7 | 6.1.0-1007.7 |
ubuntu/linux-oem-6.1 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-6.8 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oem-osp1 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oracle | <4.15.0-1116.127 | 4.15.0-1116.127 |
ubuntu/linux-oracle | <5.4.0-1094.103 | 5.4.0-1094.103 |
ubuntu/linux-oracle | <5.15.0-1032.38 | 5.15.0-1032.38 |
ubuntu/linux-oracle | <5.19.0-1019.22 | 5.19.0-1019.22 |
ubuntu/linux-oracle | <6.2.0-1002.2 | 6.2.0-1002.2 |
ubuntu/linux-oracle | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oracle | <4.15.0-1116.127~16.04.1 | 4.15.0-1116.127~16.04.1 |
ubuntu/linux-oracle-5.0 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oracle-5.13 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oracle-5.15 | <5.15.0-1032.38~20.04.1 | 5.15.0-1032.38~20.04.1 |
ubuntu/linux-oracle-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oracle-5.4 | <5.4.0-1094.103~18.04.1 | 5.4.0-1094.103~18.04.1 |
ubuntu/linux-oracle-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-oracle-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-raspi | <5.4.0-1081.92 | 5.4.0-1081.92 |
ubuntu/linux-raspi | <5.15.0-1026.28 | 5.15.0-1026.28 |
ubuntu/linux-raspi | <5.19.0-1015.22 | 5.19.0-1015.22 |
ubuntu/linux-raspi | <6.2.0-1003.3 | 6.2.0-1003.3 |
ubuntu/linux-raspi | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-raspi-5.4 | <5.4.0-1081.92~18.04.1 | 5.4.0-1081.92~18.04.1 |
ubuntu/linux-raspi-5.4 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-raspi2 | <4.15.0-1129.137 | 4.15.0-1129.137 |
ubuntu/linux-raspi2 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-riscv | <5.19.0-1015.16 | 5.19.0-1015.16 |
ubuntu/linux-riscv | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-riscv-5.15 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-riscv-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-snapdragon | <4.15.0-1148.158 | 4.15.0-1148.158 |
ubuntu/linux-snapdragon | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-starfive | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-starfive-6.5 | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
ubuntu/linux-xilinx-zynqmp | <6.2~<5.4.229<5.15.87 | 6.2~ 5.4.229 5.15.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)