FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- arm64 boot CPUs may lack speculative execution protections

Affected packages
13.2 <= FreeBSD-kernel < 13.2_4

Details

VuXML ID 162a675b-6251-11ee-8e38-002590c1f29c
Discovery 2023-10-03
Entry 2023-10-04

Problem Description:

On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized.

Impact:

No speculative execution workarounds are installed on CPU 0.

References

CVE Name CVE-2023-5370
FreeBSD Advisory SA-23:14.smccc