PT-2020-6171 · Ibm+9 · Power9+12

Published

2020-11-19

·

Updated

2023-02-03

·

CVE-2020-4788

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors IBM Power9 processors
Description The issue is related to speculation on incompletely validated data, which could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. This is a problem of information disclosure.
Recommendations For IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors, consider restricting access to sensitive data to minimize the risk of exploitation. For IBM Power9 processors, as a temporary workaround, consider disabling speculative execution on incompletely validated data until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
ALT-PU-2020-3388
ALT-PU-2020-3389
ALT-PU-2020-3408
ALT-PU-2020-3410
ALT-PU-2020-3470
ALT-PU-2020-3536
ALT-PU-2021-1083
ALT-PU-2021-1211
ALT-PU-2021-1745
BDU:2021-03412
CESA-2022_1988
CVE-2020-4788
DLA-2483-1
OPENSUSE-SU-2020:2161-1
OPENSUSE-SU-2020:2193-1
OPENSUSE-SU-2020:2260-1
OPENSUSE-SU-2020_2161-1
OPENSUSE-SU-2020_2193-1
OPENSUSE-SU-2020_2260-1
OPENSUSE-SU-2021:0075-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_0075-1
OPENSUSE-SU-2021_0242-1
OPENSUSE-SU-2021_3876-1
RHSA-2022:1988
RHSA-2022_1988
RLSA-2022:1988
SUSE-SU-2020:3713-1
SUSE-SU-2020:3748-1
SUSE-SU-2020:3764-1
SUSE-SU-2020:3766-1
SUSE-SU-2020:3798-1
SUSE-SU-2021:0097-1
SUSE-SU-2021:0098-1
SUSE-SU-2021:0118-1
SUSE-SU-2021:0133-1
SUSE-SU-2021:0434-1
SUSE-SU-2021:0438-1
SUSE-SU-2021:0452-1
SUSE-SU-2021:14630-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3935-1
SUSE-SU-2021_14630-1
USN-4657-1
USN-4658-1
USN-4658-2
USN-4659-1
USN-4660-1
USN-4660-2
USN-4681-1

Affected Products

Aix
Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Power9
Red Hat
Rocky Linux
Suse
Ubuntu
Vios