Skip to content

kernel CVE-2022-0002

High
cbgbt published GHSA-pfp7-3vw9-2g3m Mar 9, 2022

Package

kernel (bottlerocket)

Affected versions

< 1.6.2

Patched versions

1.6.2

Description

Non-transparent sharing of branch predictor within a context in some Intel Processors may allow an authorized user to potentially enable information disclosure via local access.

Unprivileged eBPF has always been disabled by default in Bottlerocket, which mitigates the current known vector to exploit this vulnerability.

Severity

High

CVE ID

CVE-2022-0002

Weaknesses

No CWEs