---
id: CVE-2022-23960
title: >-
  Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly
  restrict cache speculation, aka Spectre-BHB
summary: >-
  Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly
  restrict cache speculation, aka Spectre-BHB. An attacker can leverage the
  shared branch history in the Branch History Buffer (BHB) to influence
  mispredicted br…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'
vendor: xen
product: xen
affected:
  - xen
  - cortex-r7_firmware
  - cortex-r8_firmware
  - cortex-a57_firmware
  - cortex-a65_firmware
  - cortex-a65ae_firmware
  - cortex-a710_firmware
  - cortex-a72_firmware
  - cortex-a73_firmware
  - cortex-a75_firmware
  - cortex-a76_firmware
  - cortex-a76ae_firmware
  - cortex-a77_firmware
  - cortex-a78_firmware
  - cortex-a78ae_firmware
  - cortex-x1_firmware
  - cortex-x2_firmware
  - neoverse-e1_firmware
  - neoverse-v1_firmware
  - neoverse_n1_firmware
  - neoverse_n2_firmware
  - debian_linux = 9.0
  - debian_linux = 10.0
published: '2022-03-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:19.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23960'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2022/03/18/2'
    label: cve@mitre.org
  - url: 'https://developer.arm.com/support/arm-security-updates'
    label: cve@mitre.org
  - url: >-
      https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2022/dsa-5173'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2022/03/18/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://developer.arm.com/support/arm-security-updates'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5173'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00499
epssPercentile: 0.40833
ingestedAt: '2026-10-08T23:16:47.339Z'
---

## Overview

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

## Affected

- `xen`
- `cortex-r7_firmware`
- `cortex-r8_firmware`
- `cortex-a57_firmware`
- `cortex-a65_firmware`
- `cortex-a65ae_firmware`
- `cortex-a710_firmware`
- `cortex-a72_firmware`
- `cortex-a73_firmware`
- `cortex-a75_firmware`
- `cortex-a76_firmware`
- `cortex-a76ae_firmware`
- `cortex-a77_firmware`
- `cortex-a78_firmware`
- `cortex-a78ae_firmware`
- `cortex-x1_firmware`
- `cortex-x2_firmware`
- `neoverse-e1_firmware`
- `neoverse-v1_firmware`
- `neoverse_n1_firmware`
- `neoverse_n2_firmware`
- `debian_linux = 9.0`
- `debian_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
