Spectre V1 Gadget in do_prlimit in the Linux Kernel
Published Apr 26, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.72%
Description
A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit 739790605705ddcf18f21782b9c99ad7d53a8c11
Affected products
-
- Version 0StatusaffectedConstraints<=6.1.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | unaffected |
|
Configuration 1
- < 6.1.8
- 6.2
- 6.2
- 6.2
- 6.2
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.43.1.el8_8
Fixed · RHSA-2024:0575
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.25.1.el9_2
Fixed · RHSA-2023:4377
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.25.1.el9_2
Fixed · RHSA-2023:4377
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.25.1.rt14.310.el9_2
Fixed · RHSA-2023:4378
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.70.1.el9_0
Fixed · RHSA-2023:4801
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.70.1.rt21.141.el9_0
Fixed · RHSA-2023:4814
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.43.1.el8_8 | Fixed | RHSA-2024:0575 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.25.1.el9_2 | Fixed | RHSA-2023:4377 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.25.1.el9_2 | Fixed | RHSA-2023:4377 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.25.1.rt14.310.el9_2 | Fixed | RHSA-2023:4378 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.70.1.el9_0 | Fixed | RHSA-2023:4801 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.70.1.rt21.141.el9_0 | Fixed | RHSA-2023:4814 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2023-0458 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2193219 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12512 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/diff/kernel/sys.c?id=v6.1.8&id2=v6.1.7 Patch
- https://github.com/torvalds/linux/commit/739790605705ddcf18f21782b9c99ad7d53a8c11 Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-0458
- https://www.cve.org/CVERecord?id=CVE-2023-0458
Change history (0)
No recorded changes yet.