Description
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.
Published: 2022-03-09
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-30039 Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.
History

No history.

Subscriptions

Amperecomputing Ampere Altra Ampere Altra Firmware Ampere Altra Max Ampere Altra Max Firmware
Arm Cortex-a15 Cortex-a15 Firmware Cortex-a57 Cortex-a57 Firmware Cortex-a65 Cortex-a65 Firmware Cortex-a65ae Cortex-a65ae Firmware Cortex-a710 Cortex-a710 Firmware Cortex-a72 Cortex-a72 Firmware Cortex-a73 Cortex-a73 Firmware Cortex-a75 Cortex-a75 Firmware Cortex-a76 Cortex-a76 Firmware Cortex-a76ae Cortex-a76ae Firmware Cortex-a77 Cortex-a77 Firmware Cortex-a78 Cortex-a78 Firmware Cortex-a78ae Cortex-a78ae Firmware Cortex-a78c Cortex-a78c Firmware Cortex-x1 Cortex-x1 Firmware Cortex-x2 Cortex-x2 Firmware Neoverse-e1 Neoverse-e1 Firmware Neoverse-v1 Neoverse-v1 Firmware Neoverse N1 Neoverse N1 Firmware Neoverse N2 Neoverse N2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T04:36:06.904Z

Reserved: 2022-02-19T00:00:00.000Z

Link: CVE-2022-25368

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-10T17:47:07.880

Modified: 2024-11-21T06:52:05.403

Link: CVE-2022-25368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses