Lucene search

K
redhatcveRedhat.comRH:CVE-2023-0045
HistoryFeb 06, 2023 - 6:56 a.m.

CVE-2023-0045

2023-02-0606:56:20
redhat.com
access.redhat.com
81
linux kernel
spectre-bti attack
ibpb
vulnerability
mitigation
user-mode
reschedule

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.1%

A flaw was found in the Linux kernel. This issue occurs due to a failure mitigating the Spectre-BTI attack (using the kernel API), as IBPB is not issued during the syscall until the next schedule, leaving the system vulnerable.

Mitigation

For user-mode applications, a usleep after the prctl call will force a reschedule and ensure the correct mitigation.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.1%