Spectre v2 SMT mitigations problem in Linux kernel
Published Apr 21, 2023
5.6
MEDIUMCVSS 3.1
EPSS 1.38%
Description
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel still left the victim process exposed to attacks in some cases even after enabling the spectre-BTI mitigation with prctl. The same behavior can be observed on a bare-metal machine when forcing the mitigation to IBRS on boot command line.
This happened because when plain IBRS was enabled (not enhanced IBRS), the kernel had some logic that determined that STIBP was not needed. The IBRS bit implicitly protects against cross-thread branch target injection. However, with legacy IBRS, the IBRS bit was cleared on returning to userspace, due to performance reasons, which disabled the implicit STIBP and left userspace threads vulnerable to cross-thread branch target injection against which STIBP protects.
Affected products
-
- Version 0StatusaffectedConstraints<6.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | unaffected |
|
Configuration 1
- < 6.3
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.58.1.el8_8
Fixed · RHSA-2024:3810
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.25.1.el9_2
Fixed · RHSA-2023:4377
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.25.1.el9_2
Fixed · RHSA-2023:4377
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.25.1.rt14.310.el9_2
Fixed · RHSA-2023:4378
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.75.1.el9_0
Fixed · RHSA-2023:5604
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.75.1.rt21.146.el9_0
Fixed · RHSA-2023:5603
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.58.1.el8_8 | Fixed | RHSA-2024:3810 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.25.1.el9_2 | Fixed | RHSA-2023:4377 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.25.1.el9_2 | Fixed | RHSA-2023:4377 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.25.1.rt14.310.el9_2 | Fixed | RHSA-2023:4378 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.75.1.el9_0 | Fixed | RHSA-2023:5604 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.75.1.rt21.146.el9_0 | Fixed | RHSA-2023:5603 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
This flaw can be mitigated by disabling Simultaneous Multithreading (SMT). For instructions on how to disable SMT in RHEL, please see https://access.redhat.com/solutions/rhel-smt.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.38% (0.01377) | 71.07th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.38% (0.01377) | 68.41th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00042) | 9.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00055) | 24.86th | v3 (v2023.03.01) |
| May 10, 2024 | 0.04% (0.00045) | 14.77th | v3 (v2023.03.01) |
| Oct 11, 2023 | 0.04% (0.00045) | 12.72th | v3 (v2023.03.01) |
| May 4, 2023 | 0.04% (0.00044) | 10.72th | v3 (v2023.03.01) |
| Apr 22, 2023 | 0.08% (0.00082) | 33.38th | v3 (v2023.03.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2023-1998 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2187257 Issue Tracking
- https://github.com/google/security-research/security/advisories/GHSA-mj4w-6495-6crx ExploitThird Party Advisory
- https://github.com/torvalds/linux/commit/6921ed9049bc7457f66c1596c5b78aec0dae4a9d Patch
- https://kernel.dance/#6921ed9049bc7457f66c1596c5b78aec0dae4a9d Not Applicable
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-1998
- https://www.cve.org/CVERecord?id=CVE-2023-1998
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-1998 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2187257 | Issue Tracking | |
| https://github.com/google/security-research/security/advisories/GHSA-mj4w-6495-6crx | ExploitThird Party Advisory | |
| https://github.com/torvalds/linux/commit/6921ed9049bc7457f66c1596c5b78aec0dae4a9d | Patch | |
| https://kernel.dance/#6921ed9049bc7457f66c1596c5b78aec0dae4a9d | Not Applicable | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html | Mailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html | Mailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-1998 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-1998 |
Change history (0)
No recorded changes yet.