On Thu, 2026-08-06 at 17:04 +0000, Venkata Navduri wrote:
> From: Navuduri Venkata Adhitya <[email protected]>
> 
> The x86 cpu_entry_area KASLR bypass (CVE-2023-3640) was fixed in
> v6.2-rc1 by commit 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry
> area") from Peter Zijlstra.
> 
> The fix is already present in all Yocto releases shipping kernel >=6.2.
> 
> Signed-off-by: Navuduri Venkata Adhitya <[email protected]>

Hi,

Commit 97e3d26b5e5f371b3ee223d94dd123e6c442ba80 is the fix for
CVE-2023-0597 [1].

On NVD, the description of CVE-2023-3640 [2] includes:

  Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry
  area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which
  works through the init_cea_offsets() function when KASLR is enabled.
  However, despite this feature, there is still a risk of per-cpu entry
  area leaks.

So this CVE appears to be about remaining issues after the fix in that
commit.

[1]: https://nvd.nist.gov/vuln/detail/cve-2023-0597
[2]: https://nvd.nist.gov/vuln/detail/cve-2023-3640

Best regards,

-- 
Paul Barker

Attachment: signature.asc
Description: This is a digitally signed message part

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243000): 
https://lists.openembedded.org/g/openembedded-core/message/243000
Mute This Topic: https://lists.openembedded.org/mt/120640317/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • Re: [OE-core] [PATCH]... Paul Barker

Reply via email to