ZeroHour

CVE-2022-25368

CVSS 3.1
4.7 medium
EPSS
<1%p22
Published
()
Modified
Description

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

Vendors
amperecomputingarm
Products
ampere altra max firmware, ampere altra firmware, neoverse-e1 firmware, neoverse-v1 firmware, cortex-a57 firmware, cortex-a65 firmware, cortex-a65ae firmware, cortex-a72 firmware, cortex-a73 firmware, cortex-a75 firmware, cortex-a76 firmware, cortex-a76ae firmware
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.