A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.
References
Link | Resource |
---|---|
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e2a1256b17b16f9b9adf1b6fea56819e7b68e463 | Mailing List Patch |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e2a1256b17b16f9b9adf1b6fea56819e7b68e463 | Mailing List Patch |
https://sourceware.org/bugzilla/show_bug.cgi?id=27398 | Issue Tracking |
https://sourceware.org/bugzilla/show_bug.cgi?id=27398 | Issue Tracking |
https://sourceware.org/bugzilla/show_bug.cgi?id=27398 | Issue Tracking |
Configurations
History
19 Feb 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e2a1256b17b16f9b9adf1b6fea56819e7b68e463 - Mailing List, Patch | |
References | () https://sourceware.org/bugzilla/show_bug.cgi?id=27398 - Issue Tracking |
03 Apr 2023, 18:06
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linux linux Kernel
Linux |
|
CPE | cpe:2.3:o:linux:linux_kernel:5.18:rc2:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CWE | CWE-212 | |
References | (MISC) https://sourceware.org/bugzilla/show_bug.cgi?id=27398 - Issue Tracking | |
References | (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e2a1256b17b16f9b9adf1b6fea56819e7b68e463 - Mailing List, Patch |
Information
Published : 2023-03-27 22:15
Updated : 2025-02-19 21:15
NVD link : CVE-2023-1637
Mitre link : CVE-2023-1637
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer