7.5

CVE-2023-0045

Exploit

Incorrect indirect branch prediction barrier in the Linux Kernel

The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set  function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the victim vulnerable to values already injected on the BTB, prior to the prctl syscall.  The patch that added the support for the conditional mitigation via prctl (ib_prctl_set) dates back to the kernel 4.9.176.

We recommend upgrading past commit a664ec9158eeddd75121d39c9a0758016097fa96
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.16.68 < 3.17
Linux ≫ Linux Kernel Version >= 4.4.180 < 4.5
Linux ≫ Linux Kernel Version >= 4.9.176 < 4.10
Linux ≫ Linux Kernel Version >= 4.14.86 < 4.14.303
Linux ≫ Linux Kernel Version >= 4.19.7 < 4.19.270
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.229
Linux ≫ Linux Kernel Version >= 5.5.0 < 5.10.163
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.87
Linux ≫ Linux Kernel Version >= 5.16 < 6.0.19
Linux ≫ Linux Kernel Version >= 6.1 < 6.1.5
Debian ≫ Debian Linux Version 10.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.4% 0.819
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cve-coordination@google.com 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
Third Party Advisory
Mailing List
https://git.kernel.org/tip/a664ec9158eeddd75121d39c9a0758016097fa96
Patch
Mailing List
https://github.com/google/security-research/security/advisories/GHSA-9x5g-vmxf-4qj8
Third Party Advisory
Exploit
https://security.netapp.com/advisory/ntap-20230714-0001/
Third Party Advisory