CVE-2023-5370: arm64 boot CPUs may lack speculative execution protections
On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5370?
CVE-2023-5370 is a vulnerability that occurs when the check for the SMCCC workaround is called before SMCCC support has been initialized, resulting in no speculative execution workarounds being installed on CPU 0.
How does CVE-2023-5370 affect FreeBSD 13.2?
CVE-2023-5370 affects FreeBSD 13.2 by leaving CPU 0 vulnerable to speculative execution attacks because the necessary workarounds are not installed.
What is the severity of CVE-2023-5370?
The severity of CVE-2023-5370 is rated as medium with a severity value of 5.5.
How can CVE-2023-5370 be fixed?
To fix CVE-2023-5370, it is recommended to apply the necessary patches provided by FreeBSD.
Where can I find more information about CVE-2023-5370?
You can find more information about CVE-2023-5370 in the advisory published on the FreeBSD Security website.