Bug 2061721 (CVE-2022-0002) - CVE-2022-0002 hw: cpu: intel: Intra-Mode BTI
Summary: CVE-2022-0002 hw: cpu: intel: Intra-Mode BTI
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-0002
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2062155 2062156 2062157 2062158 2062159 2062160 2062161 2062634
Blocks: 2012088
TreeView+ depends on / blocked
 
Reported: 2022-03-08 12:06 UTC by Petr Matousek
Modified: 2022-06-16 11:24 UTC (History)
33 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
A flaw was found in hw. The Intra-mode BTI refers to a variant of Branch Target Injection aka SpectreV2 (BTI) where an indirect branch speculates to an aliased predictor entry for a different indirect branch in the same predictor mode, and a disclosure gadget at the predicted target transiently executes. These predictor entries may contain targets corresponding to the targets of an indirect near jump, indirect near call, and near return instructions, even if these branches were only transiently executed. The managed runtimes provide an attacker with the means to create the aliasing required for intra-mode BTI attacks.
Clone Of:
Environment:
Last Closed: 2022-05-11 17:45:21 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2022:2229 0 None None None 2022-05-12 11:27:22 UTC
Red Hat Product Errata RHBA-2022:4630 0 None None None 2022-05-18 11:47:08 UTC
Red Hat Product Errata RHBA-2022:4693 0 None None None 2022-05-19 05:11:34 UTC
Red Hat Product Errata RHBA-2022:4969 0 None None None 2022-06-08 18:40:42 UTC
Red Hat Product Errata RHBA-2022:5088 0 None None None 2022-06-16 11:24:04 UTC
Red Hat Product Errata RHSA-2022:1975 0 None None None 2022-05-10 14:41:19 UTC
Red Hat Product Errata RHSA-2022:1988 0 None None None 2022-05-10 14:47:37 UTC

Description Petr Matousek 2022-03-08 12:06:40 UTC
Intra-mode BTI refers to a variant of BTI (Branch Target Injection aka SpectreV2) where an indirect branch speculates to an aliased predictor entry for a different indirect branch in the same predictor mode , and a disclosure gadget at the predicted target will transiently execute. Such predictor entries may contain targets corresponding to the targets of indirect near jump, indirect near call and/or near return instructions, even if these branches were only transiently executed. Managed runtimes can provide an attacker with the means to create the aliasing required for intra-mode BTI attacks.

Comment 4 errata-xmlrpc 2022-05-10 14:41:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1975 https://access.redhat.com/errata/RHSA-2022:1975

Comment 5 errata-xmlrpc 2022-05-10 14:47:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1988 https://access.redhat.com/errata/RHSA-2022:1988

Comment 6 Product Security DevOps Team 2022-05-11 17:45:17 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-0002


Note You need to log in before you can comment on or make changes to this bug.