In the Linux kernel, the following vulnerability has been resolved:
cpu: Re-enable CPU mitigations by default for !X86 architectures
Rename x86's to CPU_MITIGATIONS, define it in generic code, and force it on for all architectures exception x86. A recent commit to turn mitigations off by default if SPECULATION_MITIGATIONS=n kinda sorta missed that "cpu_mitigations" is completely generic, whereas SPECULATION_MITIGATIONS is x86-specific.
Rename x86's SPECULATIVE_MITIGATIONS instead of keeping both and have it select CPU_MITIGATIONS, as having two configs for the same thing is unnecessary and confusing. This will also allow x86 to use the knob to manage mitigations that aren't strictly related to speculative execution.
Use another Kconfig to communicate to common code that CPU_MITIGATIONS is already defined instead of having x86's menu depend on the common CPU_MITIGATIONS. This allows keeping a single point of contact for all of x86's mitigations, and it's not clear that other architectures *want* to allow disabling mitigations at compile-time.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade perfUpgrade bpftoolUpgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-livepatch-5.15.158-103.164Upgrade kernel-develUpgrade python-perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernelUpgrade kernel-headersUpgrade kernel-toolsUpgrade python-perf | May 22, 2025 | May 20, 2024 |
| Amazon_linux_2023 | — | Upgrade kernelUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade kernel-modules-extraUpgrade bpftoolUpgrade kernel-libbpf-staticUpgrade bpftool-debuginfoUpgrade kernel-debuginfoUpgrade kernel-libbpfUpgrade kernel-modules-extra-commonUpgrade python3-perf-debuginfoUpgrade kernel-libbpf-develUpgrade perf-debuginfoUpgrade kernel-tools-develUpgrade kernel-toolsUpgrade kernel-tools-debuginfoUpgrade kernel-develUpgrade python3-perfUpgrade perfUpgrade kernel-livepatch-6.1.90-99.173Upgrade kernel-debuginfo-common-aarch64 | Jun 11, 2025 | May 20, 2024 |
| Debian | — | Upgrade linux | Jun 27, 2024 | May 20, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 20, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1012-azure-fdeUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1011-nvidiaUpgrade linux-image-6.8.0-1010-oracleUpgrade linux-image-6.8.0-1011-nvidia-lowlatency-64kUpgrade linux-image-generic-lpaeUpgrade linux-image-6.8.0-1011-nvidia-lowlatencyUpgrade linux-image-6.8.0-1008-gkeUpgrade linux-image-oracleUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-40-lowlatency-64kUpgrade linux-image-6.8.0-1011-nvidia-64kUpgrade linux-image-6.8.0-40-lowlatencyUpgrade linux-image-ibm-classicUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-ibmUpgrade linux-image-lowlatency-64kUpgrade linux-image-lowlatencyUpgrade linux-image-awsUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-gkeUpgrade linux-image-oem-24.04Upgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-1012-gcpUpgrade linux-image-6.8.0-1012-azureUpgrade linux-image-6.8.0-1010-oracle-64kUpgrade linux-image-generic-64kUpgrade linux-image-azureUpgrade linux-image-6.8.0-40-genericUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-40-generic-64kUpgrade linux-image-6.8.0-1009-raspiUpgrade linux-image-nvidia-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-raspiUpgrade linux-image-6.8.0-1010-ibmUpgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1010-oemUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1013-awsUpgrade linux-image-kvmUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-genericUpgrade linux-image-azure-fdeUpgrade linux-image-nvidiaUpgrade linux-image-gcp | Aug 9, 2024 | May 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub