CVE-2022-4543, dubbed "EntryBleed," is a local information disclosure vulnerability affecting the Linux Kernel's Page Table Isolation (KPTI) on Intel systems. It allows a local attacker to leak the Kernel Address Space Layout Randomization (KASLR) base through prefetch side-channels based on TLB timing. Rated Medium (CVSS 5.5), this flaw requires local access and has a high impact on confidentiality, but no impact on integrity or availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
Jan 10, 2023kernel: KASLR Prefetch Bypass Breaks KPTI
Dec 19, 2022