{"id":"CVE-2022-23960","title":"Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB","summary":"Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted br…","severity":"medium","cvss":5.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","vendor":"xen","product":"xen","affected":["xen","cortex-r7_firmware","cortex-r8_firmware","cortex-a57_firmware","cortex-a65_firmware","cortex-a65ae_firmware","cortex-a710_firmware","cortex-a72_firmware","cortex-a73_firmware","cortex-a75_firmware","cortex-a76_firmware","cortex-a76ae_firmware","cortex-a77_firmware","cortex-a78_firmware","cortex-a78ae_firmware","cortex-x1_firmware","cortex-x2_firmware","neoverse-e1_firmware","neoverse-v1_firmware","neoverse_n1_firmware","neoverse_n2_firmware","debian_linux = 9.0","debian_linux = 10.0"],"published":"2022-03-13","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:19.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-23960","references":[{"url":"http://www.openwall.com/lists/oss-security/2022/03/18/2","label":"cve@mitre.org"},{"url":"https://developer.arm.com/support/arm-security-updates","label":"cve@mitre.org"},{"url":"https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2022/dsa-5173","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2022/03/18/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://developer.arm.com/support/arm-security-updates","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5173","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00499,"epssPercentile":0.40833,"ingestedAt":"2026-10-08T23:16:47.339Z","slug":"CVE-2022-23960","body":"## Overview\n\nCertain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.\n\n## Affected\n\n- `xen`\n- `cortex-r7_firmware`\n- `cortex-r8_firmware`\n- `cortex-a57_firmware`\n- `cortex-a65_firmware`\n- `cortex-a65ae_firmware`\n- `cortex-a710_firmware`\n- `cortex-a72_firmware`\n- `cortex-a73_firmware`\n- `cortex-a75_firmware`\n- `cortex-a76_firmware`\n- `cortex-a76ae_firmware`\n- `cortex-a77_firmware`\n- `cortex-a78_firmware`\n- `cortex-a78ae_firmware`\n- `cortex-x1_firmware`\n- `cortex-x2_firmware`\n- `neoverse-e1_firmware`\n- `neoverse-v1_firmware`\n- `neoverse_n1_firmware`\n- `neoverse_n2_firmware`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}