In the Linux kernel, the following vulnerability has been resolved:
cpu: Re-enable CPU mitigations by default for !X86 architectures
Rename x86's to CPU_MITIGATIONS, define it in generic code, and force it on for all architectures exception x86. A recent commit to turn mitigations off by default if SPECULATION_MITIGATIONS=n kinda sorta missed that "cpu_mitigations" is completely generic, whereas SPECULATION_MITIGATIONS is x86-specific.
Rename x86's SPECULATIVE_MITIGATIONS instead of keeping both and have it select CPU_MITIGATIONS, as having two configs for the same thing is unnecessary and confusing. This will also allow x86 to use the knob to manage mitigations that aren't strictly related to speculative execution.
Use another Kconfig to communicate to common code that CPU_MITIGATIONS is already defined instead of having x86's menu depend on the common CPU_MITIGATIONS. This allows keeping a single point of contact for all of x86's mitigations, and it's not clear that other architectures *want* to allow disabling mitigations at compile-time.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfoUpgrade bpftoolUpgrade perfUpgrade kernel-tools-debuginfoUpgrade kernel-livepatch-5.15.158-103.164Upgrade kernel-tools-develUpgrade kernel-develUpgrade perf-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade kernelUpgrade python-perfUpgrade kernel-toolsUpgrade kernel-headersUpgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfo | May 22, 2025 | May 20, 2024 |
| Amazon_linux_2023 | — | Upgrade python3-perfUpgrade kernel-develUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-debuginfoUpgrade perf-debuginfoUpgrade kernel-toolsUpgrade kernel-livepatch-6.1.90-99.173Upgrade perfUpgrade kernel-headersUpgrade kernel-libbpf-develUpgrade bpftoolUpgrade kernel-libbpfUpgrade kernel-libbpf-staticUpgrade bpftool-debuginfoUpgrade kernel-debuginfoUpgrade kernel-modules-extra-commonUpgrade python3-perf-debuginfoUpgrade kernel-modules-extraUpgrade kernelUpgrade kernel-debuginfo-common-x86_64 | Jun 11, 2025 | May 20, 2024 |
| Debian | — | Upgrade linux | Jun 27, 2024 | May 20, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 20, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1011-nvidiaUpgrade linux-image-oracleUpgrade linux-image-6.8.0-1010-oracleUpgrade linux-image-6.8.0-1012-azure-fdeUpgrade linux-image-6.8.0-40-lowlatencyUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-ibm-classicUpgrade linux-image-virtualUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-gkeUpgrade linux-image-ibmUpgrade linux-image-6.8.0-1008-gkeUpgrade linux-image-6.8.0-1011-nvidia-lowlatency-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-lowlatency-64kUpgrade linux-image-awsUpgrade linux-image-6.8.0-1011-nvidia-lowlatencyUpgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-1011-nvidia-64kUpgrade linux-image-6.8.0-40-lowlatency-64kUpgrade linux-image-generic-lpaeUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.8.0-1010-ibmUpgrade linux-image-azure-fdeUpgrade linux-image-6.8.0-1013-awsUpgrade linux-image-gcpUpgrade linux-image-nvidiaUpgrade linux-image-genericUpgrade linux-image-kvmUpgrade linux-image-6.8.0-1012-gcpUpgrade linux-image-6.8.0-1009-raspiUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-azureUpgrade linux-image-6.8.0-40-genericUpgrade linux-image-oem-24.04aUpgrade linux-image-oem-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1010-oemUpgrade linux-image-6.8.0-1012-azureUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-nvidia-64kUpgrade linux-image-generic-64kUpgrade linux-image-6.8.0-40-generic-64kUpgrade linux-image-nvidia-6.8Upgrade linux-image-raspiUpgrade linux-image-6.8.0-1010-oracle-64k | Aug 9, 2024 | May 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub