Processor optimization removal or modification of security-critical code in ARM products - CVE-2022-23960
Published: July 7, 2022
Vulnerability details
The vulnerability allows a local user to obtain potentially sensitive information.
The vulnerability exists due to improper restrictions of cache speculation. A local user can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches and gain access to sensitive information.
The vulnerability was dubbed Spectre-BHB.
Affected software
Cortex-X2
Cortex-X1
Neoverse-N2
Neoverse-V1
Neoverse-N1
Neoverse-E1
Cortex-A710
Cortex-A78AE
Cortex-A78
Cortex-R7
Cortex-A76
Cortex-A75
Cortex-A73
Cortex-A72
Cortex-A65AE
Cortex-A65
Cortex-A57
Cortex-R8
Trusted Firmware-A
Xen
Amazon Linux AMI
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Microsoft Windows
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Live Patching
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Slackware Linux
Ubuntu
openEuler
Google Android
Red Hat Virtualization Host
Red Hat OpenShift Container Platform
Dell Secure Connect Gateway
OpenShift Logging
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
kgraft-patch-4_12_14-122_116-default
kernel-azure-devel
kernel-devel-azure
kernel-source-azure
kernel-azure
kernel-azure-base
kernel-azure-base-debuginfo
kernel-azure-debuginfo
kernel-azure-debugsource
kernel-syms-azure
kernel-default-base-debuginfo
kernel-macros
kernel-devel
kernel-default-devel-debuginfo
kernel-syms
kernel-default-devel
kernel-source
kernel-default-man
kernel-default-extra
kernel-default-kgraft
kernel-default-kgraft-devel
cluster-md-kmp-default
cluster-md-kmp-default-debuginfo
dlm-kmp-default
dlm-kmp-default-debuginfo
gfs2-kmp-default
gfs2-kmp-default-debuginfo
kernel-default
ocfs2-kmp-default-debuginfo
ocfs2-kmp-default
kernel-default-debuginfo
kernel-default-debugsource
kernel-default-extra-debuginfo
kernel-obs-build
kernel-obs-build-debugsource
kernel-docs
kernel-default-base
kernel (Red Hat package)
kernel-tools-debuginfo
kernel-debuginfo
kernel-debugsource
python2-perf-debuginfo
python2-perf
kernel-tools
bpftool
perf
perf-debuginfo
kernel-tools-devel
python3-perf
bpftool-debuginfo
python3-perf-debuginfo
kernel
kernel-tools-libs-devel
kernel-tools-libs
kernel-modules-internal
kernel-modules-extra
kernel-modules
kernel-headers
python-perf
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-core
linux (Debian package)
linux-image-virtual (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-oem (Ubuntu package)
linux-image-oem-osp1 (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-5.4.0-104-lowlatency (Ubuntu package)
linux-image-5.4.0-104-generic-lpae (Ubuntu package)
linux-image-5.4.0-104-generic (Ubuntu package)
linux-image-generic-hwe-18.04 (Ubuntu package)
linux-image-lowlatency-hwe-18.04 (Ubuntu package)
linux-image-snapdragon-hwe-18.04 (Ubuntu package)
linux-image-generic-lpae-hwe-18.04 (Ubuntu package)
linux-image-virtual-hwe-18.04 (Ubuntu package)
linux-image-ibm-lts-20.04 (Ubuntu package)
linux-image-ibm (Ubuntu package)
linux-image-5.4.0-1017-ibm (Ubuntu package)
linux-image-bluefield (Ubuntu package)
linux-image-5.4.0-1030-bluefield (Ubuntu package)
linux-image-5.4.0-1036-gkeop (Ubuntu package)
linux-image-gkeop-5.4 (Ubuntu package)
linux-image-gkeop (Ubuntu package)
linux-image-raspi-hwe-18.04 (Ubuntu package)
linux-image-5.4.0-1055-raspi (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-raspi2 (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-5.4.0-1058-kvm (Ubuntu package)
linux-image-5.4.0-1065-gke (Ubuntu package)
linux-image-gke-5.4 (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-oracle-lts-20.04 (Ubuntu package)
linux-image-5.4.0-1066-oracle (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-5.4.0-1067-gcp (Ubuntu package)
linux-image-gcp-lts-20.04 (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-aws-lts-20.04 (Ubuntu package)
linux-image-5.4.0-1068-aws (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-azure-lts-20.04 (Ubuntu package)
linux-image-5.4.0-1072-azure (Ubuntu package)
linux-image-5.4.0-1072-azure-fde (Ubuntu package)
linux-image-azure-fde (Ubuntu package)
linux-image-5.13.0-35-lowlatency (Ubuntu package)
linux-image-5.13.0-35-generic (Ubuntu package)
linux-image-5.13.0-35-generic-lpae (Ubuntu package)
linux-image-5.13.0-35-generic-64k (Ubuntu package)
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-lowlatency-hwe-20.04 (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-generic-64k-hwe-20.04 (Ubuntu package)
linux-image-generic-64k (Ubuntu package)
linux-image-oem-20.04 (Ubuntu package)
linux-image-5.13.0-1010-intel (Ubuntu package)
linux-image-5.13.0-1016-kvm (Ubuntu package)
linux-image-5.13.0-1017-azure (Ubuntu package)
linux-image-5.13.0-1017-aws (Ubuntu package)
linux-image-5.13.0-1019-gcp (Ubuntu package)
linux-image-5.13.0-1020-raspi (Ubuntu package)
linux-image-5.13.0-1020-raspi-nolpae (Ubuntu package)
linux-image-raspi-nolpae (Ubuntu package)
linux-image-5.13.0-1021-oracle (Ubuntu package)
linux-image-oem-20.04c (Ubuntu package)
linux-image-oem-20.04b (Ubuntu package)
linux-image-oem-20.04d (Ubuntu package)
linux-image-5.14.0-1027-oem (Ubuntu package)
linux-5.15.38/kernel-generic
linux-5.15.38/kernel-headers
linux-5.15.38/kernel-huge
linux-5.15.38/kernel-modules
linux-image-intel (Ubuntu package)
Dell EMC VxRail Appliance
How to mitigate CVE-2022-23960
Red Hat OpenShift Container Platform - addressed in versions 4.13.35, 4.14.14
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - addressed in versions 5.3.14, 5.5.5
kgraft-patch-4_12_14-122_116-default - update to 1-8.3.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.3
kernel-azure-devel - update to 4.12.14-16.97.1
kernel-devel-azure - update to 4.12.14-16.97.1
kernel-source-azure - update to 4.12.14-16.97.1
kernel-azure - update to 4.12.14-16.97.1
kernel-azure-base - update to 4.12.14-16.97.1
kernel-azure-base-debuginfo - update to 4.12.14-16.97.1
kernel-azure-debuginfo - update to 4.12.14-16.97.1
kernel-azure-debugsource - update to 4.12.14-16.97.1
kernel-syms-azure - update to 4.12.14-16.97.1
kernel-default-base-debuginfo - update to 4.12.14-122.116.1
kernel-macros - update to 4.12.14-122.116.1
kernel-devel - update to 4.12.14-122.116.1
kernel-default-devel-debuginfo - update to 4.12.14-122.116.1
kernel-syms - update to 4.12.14-122.116.1
kernel-default-devel - update to 4.12.14-122.116.1
kernel-source - update to 4.12.14-122.116.1
kernel-default-man - update to 4.12.14-122.116.1
kernel-default-extra - update to 4.12.14-122.116.1
kernel-default-kgraft - update to 4.12.14-122.116.1
kernel-default-kgraft-devel - update to 4.12.14-122.116.1
cluster-md-kmp-default - update to 4.12.14-122.116.1
cluster-md-kmp-default-debuginfo - update to 4.12.14-122.116.1
dlm-kmp-default - update to 4.12.14-122.116.1
dlm-kmp-default-debuginfo - update to 4.12.14-122.116.1
gfs2-kmp-default - update to 4.12.14-122.116.1
gfs2-kmp-default-debuginfo - update to 4.12.14-122.116.1
kernel-default - update to 4.12.14-122.116.1
ocfs2-kmp-default-debuginfo - update to 4.12.14-122.116.1
ocfs2-kmp-default - update to 4.12.14-122.116.1
kernel-default-debuginfo - update to 4.12.14-122.116.1
kernel-default-debugsource - update to 4.12.14-122.116.1
kernel-default-extra-debuginfo - update to 4.12.14-122.116.1
kernel-obs-build - update to 4.12.14-122.116.1
kernel-obs-build-debugsource - update to 4.12.14-122.116.1
kernel-docs - update to 4.12.14-122.116.1
kernel-default-base - update to 4.12.14-122.116.1
kernel (Red Hat package) - addressed in versions 4.18.0-372.93.1.el8_6, 4.18.0-425.3.1.el8
kernel-tools-debuginfo - update to 4.19.90-2204.4.0.0148
kernel-debuginfo - update to 4.19.90-2204.4.0.0148
kernel-debugsource - update to 4.19.90-2204.4.0.0148
python2-perf-debuginfo - update to 4.19.90-2204.4.0.0148
python2-perf - update to 4.19.90-2204.4.0.0148
kernel-tools - update to 4.19.90-2204.4.0.0148
bpftool - update to 4.19.90-2204.4.0.0148
perf - update to 4.19.90-2204.4.0.0148
perf-debuginfo - update to 4.19.90-2204.4.0.0148
kernel-tools-devel - update to 4.19.90-2204.4.0.0148
python3-perf - update to 4.19.90-2204.4.0.0148
kernel-source - update to 4.19.90-2204.4.0.0148
bpftool-debuginfo - update to 4.19.90-2204.4.0.0148
python3-perf-debuginfo - update to 4.19.90-2204.4.0.0148
kernel-devel - update to 4.19.90-2204.4.0.0148
kernel - update to 4.19.90-2204.4.0.0148
perf - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-tools-libs-devel - addressed in versions 4.19.91-27.1, 4.19.91-28
bpftool - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-tools-libs - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-devel - addressed in versions 4.19.91-27.1, 4.19.91-28
python3-perf - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-tools - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-modules-internal - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-modules-extra - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-modules - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-headers - addressed in versions 4.19.91-27.1, 4.19.91-28
python-perf - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-debug-modules-extra - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-debug-modules - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-debug-devel - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-debug-core - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-debug - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel-core - addressed in versions 4.19.91-27.1, 4.19.91-28
kernel - addressed in versions 4.19.91-27.1, 4.19.91-28
linux (Debian package) - update to 4.19.249-2
linux-image-virtual (Ubuntu package) - addressed in versions 5.4.0.104.108, 5.13.0.35.44
linux-image-generic (Ubuntu package) - addressed in versions 5.4.0.104.108, 5.13.0.35.44
linux-image-oem (Ubuntu package) - addressed in versions 5.4.0.104.108, 5.4.0.104.118~18.04.89
linux-image-oem-osp1 (Ubuntu package) - addressed in versions 5.4.0.104.108, 5.4.0.104.118~18.04.89
linux-image-lowlatency (Ubuntu package) - addressed in versions 5.4.0.104.108, 5.13.0.35.44
linux-image-generic-lpae (Ubuntu package) - addressed in versions 5.4.0.104.108, 5.13.0.35.44
linux-image-5.4.0-104-lowlatency (Ubuntu package) - addressed in versions 5.4.0-104.118, 5.4.0-104.118~18.04.1
linux-image-5.4.0-104-generic-lpae (Ubuntu package) - addressed in versions 5.4.0-104.118, 5.4.0-104.118~18.04.1
linux-image-5.4.0-104-generic (Ubuntu package) - addressed in versions 5.4.0-104.118, 5.4.0-104.118~18.04.1
linux-image-generic-hwe-18.04 (Ubuntu package) - update to 5.4.0.104.118~18.04.89
linux-image-lowlatency-hwe-18.04 (Ubuntu package) - update to 5.4.0.104.118~18.04.89
linux-image-snapdragon-hwe-18.04 (Ubuntu package) - update to 5.4.0.104.118~18.04.89
linux-image-generic-lpae-hwe-18.04 (Ubuntu package) - update to 5.4.0.104.118~18.04.89
linux-image-virtual-hwe-18.04 (Ubuntu package) - update to 5.4.0.104.118~18.04.89
linux-image-ibm-lts-20.04 (Ubuntu package) - update to 5.4.0.1017.17
linux-image-ibm (Ubuntu package) - addressed in versions 5.4.0.1017.17, 5.4.0.1017.34
linux-image-5.4.0-1017-ibm (Ubuntu package) - addressed in versions 5.4.0-1017.19, 5.4.0-1017.19~18.04.1
linux-image-bluefield (Ubuntu package) - update to 5.4.0.1030.31
linux-image-5.4.0-1030-bluefield (Ubuntu package) - update to 5.4.0-1030.33
linux-image-5.4.0-1036-gkeop (Ubuntu package) - addressed in versions 5.4.0-1036.37, 5.4.0-1036.37~18.04.1
linux-image-gkeop-5.4 (Ubuntu package) - addressed in versions 5.4.0.1036.37~18.04.36, 5.4.0.1036.39
linux-image-gkeop (Ubuntu package) - update to 5.4.0.1036.39
linux-image-raspi-hwe-18.04 (Ubuntu package) - update to 5.4.0.1055.57
linux-image-5.4.0-1055-raspi (Ubuntu package) - addressed in versions 5.4.0-1055.62, 5.4.0-1055.62~18.04.1
linux-image-raspi (Ubuntu package) - addressed in versions 5.4.0.1055.89, 5.13.0.1020.25
linux-image-raspi2 (Ubuntu package) - update to 5.4.0.1055.89
linux-image-kvm (Ubuntu package) - addressed in versions 5.4.0.1058.57, 5.13.0.1016.16
linux-image-5.4.0-1058-kvm (Ubuntu package) - update to 5.4.0-1058.61
linux-image-5.4.0-1065-gke (Ubuntu package) - addressed in versions 5.4.0-1065.68, 5.4.0-1065.68~18.04.1
linux-image-gke-5.4 (Ubuntu package) - addressed in versions 5.4.0.1065.68~18.04.29, 5.4.0.1065.75
linux-image-gke (Ubuntu package) - addressed in versions 5.4.0.1065.75, 5.13.0.1019.17
linux-image-oracle-lts-20.04 (Ubuntu package) - update to 5.4.0.1066.66
linux-image-5.4.0-1066-oracle (Ubuntu package) - addressed in versions 5.4.0-1066.71, 5.4.0-1066.71~18.04.1
linux-image-oracle (Ubuntu package) - addressed in versions 5.4.0.1066.71~18.04.45, 5.13.0.1021.21, 5.13.0.1021.26~20.04.1
linux-image-gcp (Ubuntu package) - addressed in versions 5.4.0.1067.52, 5.13.0.1019.17, 5.13.0.1019.23~20.04.1
linux-image-5.4.0-1067-gcp (Ubuntu package) - addressed in versions 5.4.0-1067.71, 5.4.0-1067.71~18.04.1
linux-image-gcp-lts-20.04 (Ubuntu package) - update to 5.4.0.1067.76
linux-image-aws (Ubuntu package) - addressed in versions 5.4.0.1068.50, 5.13.0.1017.18, 5.13.0.1017.19~20.04.10
linux-image-aws-lts-20.04 (Ubuntu package) - update to 5.4.0.1068.70
linux-image-5.4.0-1068-aws (Ubuntu package) - addressed in versions 5.4.0-1068.72, 5.4.0-1068.72~18.04.1
linux-image-azure (Ubuntu package) - addressed in versions 5.4.0.1072.51, 5.13.0.1017.17, 5.13.0.1017.19~20.04.7
linux-image-azure-lts-20.04 (Ubuntu package) - update to 5.4.0.1072.70
linux-image-5.4.0-1072-azure (Ubuntu package) - addressed in versions 5.4.0-1072.75, 5.4.0-1072.75~18.04.1
linux-image-5.4.0-1072-azure-fde (Ubuntu package) - update to 5.4.0-1072.75+cvm1.1
linux-image-azure-fde (Ubuntu package) - update to 5.4.0.1072.75+cvm1.18
linux-image-5.13.0-35-lowlatency (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic-lpae (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic-64k (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-virtual-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-lowlatency-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-lpae-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-64k-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-64k (Ubuntu package) - update to 5.13.0.35.44
linux-image-oem-20.04 (Ubuntu package) - addressed in versions 5.13.0.35.44, 5.14.0.1027.24
linux-image-5.13.0-1010-intel (Ubuntu package) - update to 5.13.0-1010.10
linux-image-intel (Ubuntu package) - update to 5.13.0.1010.11
linux-image-5.13.0-1016-kvm (Ubuntu package) - update to 5.13.0-1016.17
linux-image-5.13.0-1017-azure (Ubuntu package) - update to 5.13.0-1017.19~20.04.1
linux-image-5.13.0-1017-aws (Ubuntu package) - update to 5.13.0-1017.19~20.04.1
linux-image-5.13.0-1019-gcp (Ubuntu package) - update to 5.13.0-1019.23~20.04.1
linux-image-5.13.0-1020-raspi (Ubuntu package) - update to 5.13.0-1020.22
linux-image-5.13.0-1020-raspi-nolpae (Ubuntu package) - update to 5.13.0-1020.22
linux-image-raspi-nolpae (Ubuntu package) - update to 5.13.0.1020.25
linux-image-5.13.0-1021-oracle (Ubuntu package) - update to 5.13.0-1021.26~20.04.1
linux-image-oem-20.04c (Ubuntu package) - update to 5.14.0.1027.24
linux-image-oem-20.04b (Ubuntu package) - update to 5.14.0.1027.24
linux-image-oem-20.04d (Ubuntu package) - update to 5.14.0.1027.24
linux-image-5.14.0-1027-oem (Ubuntu package) - update to 5.14.0-1027.30
linux-5.15.38/kernel-generic - update to 5.15.38
linux-5.15.38/kernel-headers - update to 5.15.38
linux-5.15.38/kernel-huge - update to 5.15.38
linux-5.15.38/kernel-modules - update to 5.15.38
kernel - update to 6.1.10-15.42
Dell EMC VxRail Appliance - update to 8.0.000
Google Android - addressed in versions 10 2022-12-05, 10 2023-01-05, 11 2022-12-05, 11 2023-01-05, 12L 2022-12-05, 12L 2023-01-05, 12 2022-12-05, 12 2023-01-05, 13 2022-12-05, 13 2023-01-05
External References
Related Security Bulletins
- Spectre-BHB vulnerability in ARM processors
- Debian update for linux
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Slackware Linux update for Slackware 15.0 kernel
- Information disclosure in Microsoft Windows
- Red Hat Enterprise Linux 8 update for kernel
- Multiple vulnerabilities in Google Android
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in Google Android
- Spectre-BHB vulnerability in Trusted Firmware-A
- SUSE update for the Linux Kernel
- SUSE update for the Linux Kernel
- Ubuntu update for linux
- Ubuntu update for linux
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8.6 Extended Update Support update for kernel
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- openEuler update for kernel
- Amazon Linux AMI update for kernel
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6
- Ubuntu update for linux-intel-5.13
- Anolis OS update for kernel(ANCK)4.19
- Anolis OS update for kernel
- Anolis OS update for kernel
- Anolis OS update for kernel
- Multiple vulnerabilities in Xen XSA