kernel: x86/mm: Randomize per-cpu entry area
Published Feb 23, 2023
7.0
HIGHCVSS 3.1
EPSS 0.30%
Description
A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.
Affected products
- Vendor n/a Product Kernel Defaultunknown
Affected
- Linux kernel 6.2-rc1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Kernel | unknown | Affected
|
- 6.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.95.1.el8_6
Fixed · RHSA-2024:1188
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.81.1.el8_8
Fixed · RHSA-2024:10262
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.95.1.el9_2
Fixed · RHSA-2024:10772
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.95.1.rt14.380.el9_2
Fixed · RHSA-2024:10773
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.95.1.el8_6
Fixed · RHSA-2024:1188
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.95.1.el8_6 | Fixed | RHSA-2024:1188 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.81.1.el8_8 | Fixed | RHSA-2024:10262 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.95.1.el9_2 | Fixed | RHSA-2024:10772 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.95.1.rt14.380.el9_2 | Fixed | RHSA-2024:10773 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.95.1.el8_6 | Fixed | RHSA-2024:1188 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2023/07/28/1 mailing-list
- https://access.redhat.com/security/cve/CVE-2023-0597 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2165926 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12635 Advisory
- https://git.kernel.org/linus/97e3d26b5e5f371b3ee223d94dd123e6c442ba80 Mailing ListPatch
- https://lore.kernel.org/lkml/Yz%2FmfJ1gjgshF19t@hirez.programming.kicks-ass.net/
- https://nvd.nist.gov/vuln/detail/CVE-2023-0597
- https://www.cve.org/CVERecord?id=CVE-2023-0597
- https://www.openwall.com/lists/oss-security/2023/07/28/1 exploit
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data