Wind River Security Vulnerability Notice: Straight-Line Speculation (CVE-2020-13844) for Wind River Linux
Arm Armv8-A core implementations utilizing speculative execution past
unconditional changes in control flow may allow unauthorized disclosure
of information to an attacker with local user access via a side-channel
analysis, aka "straight-line speculation."
Affected Windriver Linux releases:
gcc: https://gcc.gnu.org/pipermail/gcc-patches/2020-June/547520.html
llvm: http://lists.llvm.org/pipermail/llvm-dev/2020-June/142109.html
NOTE: Linux kernel can'r fully mitigate this CVE issue, it can only lower the risks.
ARM: Frequently asked questions
ARM: Vulnerability of Speculative Processors to Cache Timing Side-Channel Mechanism
We will port all necessary patches on all our supporting releases. We will continue to update this web page and once we have any progress you can get it here.
For any questions or requirements, please contact your local WR support team, or mail to security-alert@windriver.com directly.
LTS1019
...
...