In the Linux kernel, the following vulnerability has been resolved:
cpu: Re-enable CPU mitigations by default for !X86 architectures
Rename x86's to CPU_MITIGATIONS, define it in generic code, and force it on for all architectures exception x86. A recent commit to turn mitigations off by default if SPECULATION_MITIGATIONS=n kinda sorta missed that "cpu_mitigations" is completely generic, whereas SPECULATION_MITIGATIONS is x86-specific.
Rename x86's SPECULATIVE_MITIGATIONS instead of keeping both and have it select CPU_MITIGATIONS, as having two configs for the same thing is unnecessary and confusing. This will also allow x86 to use the knob to manage mitigations that aren't strictly related to speculative execution.
Use another Kconfig to communicate to common code that CPU_MITIGATIONS is already defined instead of having x86's menu depend on the common CPU_MITIGATIONS. This allows keeping a single point of contact for all of x86's mitigations, and it's not clear that other architectures *want* to allow disabling mitigations at compile-time.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade python-perfUpgrade python-perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade kernelUpgrade bpftoolUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-debuginfoUpgrade kernel-livepatch-5.15.158-103.164Upgrade kernel-tools-debuginfoUpgrade perfUpgrade perf-debuginfoUpgrade kernel-develUpgrade kernel-tools-devel | May 22, 2025 | May 20, 2024 |
| Amazon_linux_2023 | — | Upgrade bpftoolUpgrade kernel-modules-extraUpgrade kernel-debuginfoUpgrade python3-perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-libbpf-develUpgrade kernel-libbpf-staticUpgrade kernel-modules-extra-commonUpgrade kernel-libbpfUpgrade kernelUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade kernel-toolsUpgrade kernel-develUpgrade python3-perfUpgrade kernel-tools-develUpgrade perf-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-debuginfoUpgrade kernel-livepatch-6.1.90-99.173Upgrade perf | Jun 11, 2025 | May 20, 2024 |
| Debian | — | Upgrade linux | Jun 27, 2024 | May 20, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 20, 2024 |
| Ubuntu | — | Upgrade linux-image-azureUpgrade linux-image-6.8.0-1009-raspiUpgrade linux-image-oem-24.04aUpgrade linux-image-oem-24.04Upgrade linux-image-6.8.0-1010-ibmUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-nvidia-64kUpgrade linux-image-6.8.0-1012-azureUpgrade linux-image-azure-fdeUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-40-generic-64kUpgrade linux-image-6.8.0-1010-oemUpgrade linux-image-kvmUpgrade linux-image-nvidia-6.8Upgrade linux-image-generic-64kUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-1010-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-6.8.0-1013-awsUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-40-genericUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-genericUpgrade linux-image-raspiUpgrade linux-image-6.8.0-1012-gcpUpgrade linux-image-ibm-classicUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1010-oracleUpgrade linux-image-6.8.0-1011-nvidiaUpgrade linux-image-6.8.0-1008-gkeUpgrade linux-image-lowlatency-64kUpgrade linux-image-awsUpgrade linux-image-6.8.0-1011-nvidia-lowlatency-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-gkeUpgrade linux-image-6.8.0-1011-nvidia-lowlatencyUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1012-azure-fdeUpgrade linux-image-6.8.0-40-lowlatencyUpgrade linux-image-generic-lpaeUpgrade linux-image-6.8.0-40-lowlatency-64kUpgrade linux-image-lowlatencyUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.8.0-1011-nvidia-64kUpgrade linux-image-ibmUpgrade linux-image-oracle | Aug 9, 2024 | May 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub