CVE-2022-23960
Published: 8 March 2022
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
From the Ubuntu Security Team
Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano Giuffrida discovered that hardware mitigations added by ARM to their processors to address Spectre-BTI were insufficient. A local attacker could potentially use this to expose sensitive information.
Notes
Author | Note |
---|---|
sbeattie | unprivileged eBPF was already disabled by default for 5.13 and newer kernels ARM specific issue |
Mitigation
To mitigate the primary known attack vector, disable unprivileged eBPF: $ sudo sysctl kernel.unprivileged_bpf_disabled=1 or $ sudo sysctl kernel.unprivileged_bpf_disabled=2
Priority
Status
Package | Release | Status |
---|---|---|
linux-hwe Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
bionic |
Ignored
(replaced by linux-hwe-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
xenial |
Released
(4.15.0-184.194~16.04.1)
|
|
lunar |
Does not exist
|
|
linux-hwe-5.4 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
bionic |
Released
(5.4.0-117.132~18.04.1)
|
|
lunar |
Does not exist
|
|
linux-hwe-5.8 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-hwe-5.11)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-hwe-5.11 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-hwe-5.13)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-hwe-5.13 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-35.40~20.04.1)
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
bionic |
Ignored
(superseded by linux-hwe-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
trusty |
Needed
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-aws-5.0 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-aws-5.3)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-aws-5.3 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-aws-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-aws-5.4 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
bionic |
Released
(5.4.0-1078.84~18.04.1)
|
|
lunar |
Does not exist
|
|
linux-aws-5.8 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-aws-5.11)
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-aws-5.11 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-aws-5.13 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-1017.19~20.04.1)
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-aws-hwe Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
xenial |
Released
(4.15.0-1133.143~16.04.1)
|
|
lunar |
Does not exist
|
|
linux-azure-4.15 Launchpad, Ubuntu, Debian |
kinetic |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
bionic |
Released
(4.15.0-1142.156)
|
|
lunar |
Does not exist
|
|
linux-aws Launchpad, Ubuntu, Debian |
kinetic |
Not vulnerable
(5.15.0-1004.6)
|
bionic |
Released
(4.15.0-1133.143)
|
|
focal |
Released
(5.4.0-1078.84)
|
|
trusty |
Needed
|
|
impish |
Released
(5.13.0-1017.19)
|
|
jammy |
Not vulnerable
(5.15.0-1003.5)
|
|
upstream |
Released
(5.17~rc8)
|
|
xenial |
Needed
|
|
lunar |
Not vulnerable
(5.19.0-1009.9)
|
|
linux-oem-5.10 Launchpad, Ubuntu, Debian |
focal |
Ignored
(was needs-triage now end-of-life)
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-oem-5.6 Launchpad, Ubuntu, Debian |
focal |
Ignored
(was needs-triage now end-of-life)
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oem-osp1 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(was needs-triage now end-of-life)
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-azure-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Released
(5.13.0-1017.19~20.04.1)
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux Launchpad, Ubuntu, Debian |
bionic |
Released
(4.15.0-184.194)
|
focal |
Released
(5.4.0-117.132)
|
|
impish |
Released
(5.13.0-35.40)
|
|
jammy |
Not vulnerable
(5.15.0-23.23)
|
|
upstream |
Released
(5.17~rc8)
|
|
kinetic |
Not vulnerable
(5.15.0-25.25)
|
|
lunar |
Not vulnerable
(5.19.0-21.21)
|
|
Patches: Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
linux-kvm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
impish |
Released
(5.13.0-1016.17)
|
|
upstream |
Released
(5.17~rc8)
|
|
xenial |
Needed
|
|
bionic |
Released
(4.15.0-1119.123)
|
|
focal |
Released
(5.4.0-1068.72)
|
|
jammy |
Not vulnerable
(5.15.0-1004.4)
|
|
kinetic |
Not vulnerable
(5.15.0-1004.4)
|
|
lunar |
Not vulnerable
(5.19.0-1008.8)
|
|
linux-azure Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-azure-5.3)
|
focal |
Released
(5.4.0-1083.87)
|
|
impish |
Released
(5.13.0-1017.19)
|
|
jammy |
Not vulnerable
(5.15.0-1002.3)
|
|
upstream |
Released
(5.17~rc8)
|
|
trusty |
Released
(4.15.0-1142.156~14.04.1)
|
|
xenial |
Released
(4.15.0-1142.156~16.04.1)
|
|
kinetic |
Not vulnerable
(5.15.0-1003.4)
|
|
lunar |
Not vulnerable
(5.19.0-1008.8)
|
|
linux-azure-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-azure-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-azure-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1083.87~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-azure-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-azure-5.11)
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-azure-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-azure-fde Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Released
(5.15.0-1002.3)
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
focal |
Released
(5.4.0-1083.87)
|
|
linux-bluefield Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Released
(5.4.0-1040.44)
|
|
jammy |
Not vulnerable
(5.15.0-1011.13)
|
|
lunar |
Does not exist
|
|
linux-dell300x Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(4.15.0-1047.52)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-azure-edge Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-azure-5.3)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-fips Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
xenial |
Ignored
(out of standard support)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-gcp Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Ignored
(superseded by linux-gcp-5.3)
|
|
focal |
Not vulnerable
(ARM processor specific)
|
|
impish |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
xenial |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Not vulnerable
(ARM processor specific)
|
|
kinetic |
Not vulnerable
(ARM processor specific)
|
|
lunar |
Not vulnerable
(ARM processor specific)
|
|
linux-gcp-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gcp-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gcp-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gcp-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gcp-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-gcp-5.11)
|
|
impish |
Does not exist
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gcp-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gcp-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gke Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
xenial |
Ignored
(reached end of standard support)
|
|
focal |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
kinetic |
Does not exist
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
lunar |
Does not exist
|
|
linux-gke-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gke-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gke-5.3)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gke-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gke-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gke-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gkeop Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
kinetic |
Does not exist
|
|
jammy |
Not vulnerable
(5.15.0-1001.2)
|
|
lunar |
Does not exist
|
|
linux-gkeop-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(ARM processor specific)
|
|
upstream |
Not vulnerable
(ARM processor specific)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-ibm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1026.29)
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
kinetic |
Not vulnerable
(5.15.0-1002.2)
|
|
lunar |
Not vulnerable
(5.19.0-1008.8)
|
|
linux-ibm-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
bionic |
Released
(5.4.0-1028.32~18.04.1)
|
|
lunar |
Does not exist
|
|
linux-intel-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-1010.10)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oracle Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
impish |
Released
(5.13.0-1021.26)
|
|
upstream |
Released
(5.17~rc8)
|
|
bionic |
Released
(4.15.0-1098.108)
|
|
focal |
Released
(5.4.0-1076.83)
|
|
xenial |
Released
(4.15.0-1098.108~16.04.1)
|
|
jammy |
Not vulnerable
(5.15.0-1002.4)
|
|
kinetic |
Not vulnerable
(5.15.0-1002.4)
|
|
lunar |
Not vulnerable
(5.19.0-1008.8)
|
|
linux-oracle-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-oracle-5.3)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oracle-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-oracle-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oracle-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
bionic |
Released
(5.4.0-1076.83~18.04.1)
|
|
lunar |
Does not exist
|
|
linux-oracle-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oracle-5.11)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oracle-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-oracle-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-1021.26~20.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oem Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc8)
|
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-oem-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-oem-5.14 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
focal |
Released
(5.14.0-1033.36)
|
|
lunar |
Does not exist
|
|
linux-raspi Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Released
(5.4.0-1065.75)
|
|
impish |
Released
(5.13.0-1020.22)
|
|
jammy |
Not vulnerable
(5.15.0-1004.4)
|
|
upstream |
Released
(5.17~rc8)
|
|
kinetic |
Not vulnerable
(5.15.0-1005.5)
|
|
lunar |
Not vulnerable
(5.19.0-1004.10)
|
|
linux-raspi2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
focal |
Ignored
(replaced by linux-raspi)
|
|
impish |
Does not exist
|
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Released
(4.15.0-1114.122)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-raspi2-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-raspi-5.4)
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-raspi-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1065.75~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-riscv Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-riscv-5.8)
|
|
impish |
Ignored
(reached end-of-life)
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Ignored
(was needed now end-of-life)
|
|
kinetic |
Not vulnerable
(5.15.0-1007.7)
|
|
lunar |
Not vulnerable
(5.19.0-1004.4)
|
|
linux-riscv-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-riscv-5.11)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-riscv-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-snapdragon Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(4.15.0-1132.142)
|
|
upstream |
Released
(5.17~rc8)
|
|
xenial |
Ignored
(end of standard support)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-lowlatency Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Not vulnerable
(5.15.0-23.23)
|
|
kinetic |
Not vulnerable
(5.15.0-24.24)
|
|
lunar |
Not vulnerable
(5.19.0-1007.7)
|
|
linux-oem-5.17 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Not vulnerable
(5.17.0-1003.3)
|
|
upstream |
Released
(5.17~rc8)
|
|
kinetic |
Ignored
(was needs-triage now end-of-life)
|
|
lunar |
Does not exist
|
|
linux-intel-iotg Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
jammy |
Not vulnerable
(5.15.0-1004.6)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-intel-iotg-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Pending
(5.15.0-1008.11~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-lowlatency-hwe-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Not vulnerable
(5.15.0-33.34~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-hwe-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Not vulnerable
(5.15.0-33.34~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-aws-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Not vulnerable
(5.15.0-1014.18~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gcp-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Not vulnerable
(5.15.0-1006.9~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-gke-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
focal |
Not vulnerable
(5.15.0-1011.14~20.04.1)
|
|
kinetic |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-azure-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Not vulnerable
(5.15.0-1007.8~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-oracle-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Released
(5.17~rc8)
|
|
focal |
Not vulnerable
(5.15.0-1007.9~20.04.1)
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
linux-azure-fde-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
focal |
Not vulnerable
(5.15.0-1007.8~20.04.1)
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oem-6.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
kinetic |
Does not exist
|
|
jammy |
Not vulnerable
(6.0.0-1006.6)
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-oem-6.1 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
kinetic |
Does not exist
|
|
jammy |
Not vulnerable
(6.1.0-1004.4)
|
|
upstream |
Released
(5.17~rc8)
|
|
lunar |
Does not exist
|
|
linux-hwe-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Not vulnerable
|
|
kinetic |
Does not exist
|
|
upstream |
Needs triage
|
|
lunar |
Does not exist
|
|
linux-lowlatency-hwe-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Not vulnerable
|
|
kinetic |
Does not exist
|
|
upstream |
Needs triage
|
|
lunar |
Does not exist
|
|
linux-azure-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Not vulnerable
|
|
kinetic |
Does not exist
|
|
upstream |
Needs triage
|
|
lunar |
Does not exist
|
|
linux-iot Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Needs triage
|
|
linux-riscv-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Needs triage
|
|
linux-azure-fde-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Not vulnerable
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Needs triage
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.6 |
Attack vector | Local |
Attack complexity | High |
Privileges required | Low |
User interaction | None |
Scope | Changed |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23960
- https://www.vusec.net/projects/bhi-spectre-bhb/
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/spectre-bhb
- https://developer.arm.com/documentation/ka004995/latest/
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/BHI
- https://ubuntu.com/security/notices/USN-5317-1
- https://ubuntu.com/security/notices/USN-5318-1
- https://ubuntu.com/security/notices/USN-5362-1
- NVD
- Launchpad
- Debian