CVE-2022-25368 Information
Jun 07, 2022
cve
Description
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim’s hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation which can then be used to infer information that should be protected.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://amperecomputing.com/products/security-bulletins/impact-of-spectre-bhb-on-ampere.html https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/spectre-bhb https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23960
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.7
Share on: