PT-2023-2348 · Linux+9 · Linux Kernel+9

Es0J

+2

·

Published

2023-02-27

·

Updated

2024-11-21

·

CVE-2023-1998

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel version 6.2
Description The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR SET SPECULATION CTRL, which disables the speculation feature as well as by using seccomp. However, on VMs of at least one major cloud provider, the kernel still left the victim process exposed to attacks in some cases even after enabling the spectre-BTI mitigation with prctl. This happened because when plain IBRS was enabled, the kernel had some logic that determined that STIBP was not needed. The IBRS bit implicitly protects against cross-thread branch target injection. However, with legacy IBRS, the IBRS bit was cleared on returning to userspace, due to performance reasons, which disabled the implicit STIBP and left userspace threads vulnerable to cross-thread branch target injection against which STIBP protects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:4377
ALSA-2023:4378
ALSA-2023:7077
ALT-PU-2023-1878
ALT-PU-2023-1881
ALT-PU-2023-4663
ALT-PU-2023-4764
ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-26234
AZL-26368
BDU:2023-02115
CESA-2023_6901
CESA-2023_7077
CVE-2023-1998
DLA-3403-1
DLA-3404-1
GHSA-MJ4W-6495-6CRX
OESA-2023-1266
OESA-2023-1267
OESA-2023-1274
OESA-2023-1275
OPENSUSE-SU-2023_2646-1
OPENSUSE-SU-2023_2871-1
RHSA-2023:4377
RHSA-2023:4378
RHSA-2023:5603
RHSA-2023:5604
RHSA-2023:6901
RHSA-2023:7077
RHSA-2023_4377
RHSA-2023_4378
RHSA-2023_6901
RHSA-2023_7077
RHSA-2024:0412
RHSA-2024:3810
RLSA-2023:4378
ROSA-SA-2023-2189
SUSE-SU-2023:2140-1
SUSE-SU-2023:2141-1
SUSE-SU-2023:2146-1
SUSE-SU-2023:2147-1
SUSE-SU-2023:2148-1
SUSE-SU-2023:2151-1
SUSE-SU-2023:2156-1
SUSE-SU-2023:2162-1
SUSE-SU-2023:2163-1
SUSE-SU-2023:2231-1
SUSE-SU-2023:2232-1
SUSE-SU-2023:2646-1
SUSE-SU-2023:2805-1
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
USN-6033-1
USN-6171-1
USN-6172-1
USN-6185-1
USN-6187-1
USN-6207-1
USN-6222-1
USN-6223-1
USN-6256-1
USN-6739-1
USN-6740-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu