CVE-2022-23960
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB (CVE-2022-23960)
Affected
- android/:linux_kernel:
:0..* - android/:linux_kernel:
Kernel..*
Description
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
Affected operating systems
linux
debian / debian_linux10.0
linux
debian / debian_linux9.0
other
arm / cortex-a57_firmware
other
arm / cortex-a65_firmware
other
arm / cortex-a65ae_firmware
other
arm / cortex-a710_firmware
other
arm / cortex-a72_firmware
other
arm / cortex-a73_firmware
other
arm / cortex-a75_firmware
other
arm / cortex-a76_firmware
other
arm / cortex-a76ae_firmware
other
arm / cortex-a77_firmware
other
arm / cortex-a78_firmware
other
arm / cortex-a78ae_firmware
other
arm / cortex-r7_firmware
other
arm / cortex-r8_firmware
other
arm / cortex-x1_firmware
other
arm / cortex-x2_firmware
other
arm / neoverse-e1_firmware
other
arm / neoverse-v1_firmware
other
arm / neoverse_n1_firmware
other
arm / neoverse_n2_firmware
other
xen / xen
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
:0KernelMetrics
Show all metrics
References & sources
- https://source.android.com/security/bulletin/2022-12-01advisory
- https://android.googlesource.com/kernel/common/+/cf6a46ae183aaba1b08f183e3448f8756f8d68e1fix
- https://android.googlesource.com/kernel/common/+/cae54aa2645c769ba3263b1abd1e05cbd838f4a9fix
- https://android.googlesource.com/kernel/common/+/d65dd058214689b75eaeb054647493511755db97fix
- https://android.googlesource.com/kernel/common/+/a1736e3ccd78ceb797c3bc1b99b9114c2c00f450fix
- https://android.googlesource.com/kernel/common/+/910e14e7d00119a382bb22c3c40f2fd7db3bc1e4fix
- https://android.googlesource.com/kernel/common/+/124cc54b229a637e2ff7d70e5099ae4d6187e39ffix
- https://android.googlesource.com/kernel/common/+/decde029b601e1a8b09d94f0864a1f518a140fb3fix
- https://android.googlesource.com/kernel/common/+/0777e59b105c05cb46ea877130e672223e87e0e8fix
- https://android.googlesource.com/kernel/common/+/26e71fb73c4027d77a3212c8c9eff7e955e6ec45fix
- https://android.googlesource.com/kernel/common/+/5e6ae4e3cb2b045d69ac9cee1ae282d267283799fix
- https://android.googlesource.com/kernel/common/+/df38bfac784b0659f0c5eaa2b7ab7a11dfffb47efix
- https://android.googlesource.com/kernel/common/+/9811efebb90ce7ea684a5599da729465abadcc22fix
- https://android.googlesource.com/kernel/common/+/be161e5c6660b9c9ab1a2948a60a377e836b9685fix
- https://android.googlesource.com/kernel/common/+/a7cd57c87823bfe4c4eb88dfd045f242d6ddeeebfix
- https://android.googlesource.com/kernel/common/+/65b1e224b17749cad53443715dbf7f080338eac3fix
- https://android.googlesource.com/kernel/common/+/96468c6085fc87f1defb2b187bd778505723e1bcfix
- https://android.googlesource.com/kernel/common/+/c5aaa5f0d57ceb3d679f2c17bf555b29585d0f0efix
- https://android.googlesource.com/kernel/common/+/b79237c4eadebf2d40ccb55734dd86fc6cbbc803fix
- https://android.googlesource.com/kernel/common/+/150ecd86887b2571214a4d998eb8597434ebb476fix
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-08 22:17 UTC· cve@mitre.org
- Reference: http://www.openwall.com/lists/oss-security/2022/03/18/2
- Reference: https://developer.arm.com/support/arm-security-updates
- Reference: https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
- Reference: https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
- CVE Modified2026-10-08 22:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2022-23960","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-10-08 22:17 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2022/03/18/2
- Reference: https://developer.arm.com/support/arm-security-updates
- Reference: https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
- Reference: https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html