On Thu, 2026-08-06 at 17:04 +0000, Venkata Navduri wrote: > From: Navuduri Venkata Adhitya <[email protected]> > > The x86 cpu_entry_area KASLR bypass (CVE-2023-3640) was fixed in > v6.2-rc1 by commit 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry > area") from Peter Zijlstra. > > The fix is already present in all Yocto releases shipping kernel >=6.2. > > Signed-off-by: Navuduri Venkata Adhitya <[email protected]>
Hi, Commit 97e3d26b5e5f371b3ee223d94dd123e6c442ba80 is the fix for CVE-2023-0597 [1]. On NVD, the description of CVE-2023-3640 [2] includes: Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. So this CVE appears to be about remaining issues after the fix in that commit. [1]: https://nvd.nist.gov/vuln/detail/cve-2023-0597 [2]: https://nvd.nist.gov/vuln/detail/cve-2023-3640 Best regards, -- Paul Barker
signature.asc
Description: This is a digitally signed message part
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243000): https://lists.openembedded.org/g/openembedded-core/message/243000 Mute This Topic: https://lists.openembedded.org/mt/120640317/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
