Back

MEDIUM

kernel: KASLR Prefetch Bypass Breaks KPTI

Published Jan 11, 2023

Description

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 11, 2023
Updated Apr 8, 2025
Reserved Dec 16, 2022
CISA Vulnrichment
Updated Apr 8, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 19, 2022
ENISA EUVD
Assigner redhat
Published Jan 11, 2023
Updated Apr 8, 2025
Exploited since n/a
EUVD-2022-51878