Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-0045

25
FAUCET Score

CVE-2023-0045 describes a vulnerability in the Linux kernel's prctl syscall implementation, specifically affecting how speculative execution mitigations are applied. The flaw, present since kernel version 4.9.176, allows for a brief window where previously injected Branch Target Buffer (BTB) values can be exploited before the mitigation is fully active, impacting systems running Debian, Linux, and NetApp products. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and no user interaction required, potentially leading to high confidentiality impacts. The EPSS score is low, indicating a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.16.68, < 3.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.4.180, < 4.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.9.176, < 4.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.14.86, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.19.7, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.40%
Probability of exploitation in next 30 days
EPSS Percentile
82.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0240 is in the 68th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-0045Low

kernel: Bypassing Spectre-BTI User Space Mitigations

Feb 3, 2023

References

github.com / google/security-research/security/advisories/GHSA-9x5g-vmxf-4qj8
ExploitThird Party Advisory
git.kernel.org / tip/a664ec9158eeddd75121d39c9a0758016097fa96
Mailing ListPatch
lists.debian.org / debian-lts-announce/2023/05/msg00005.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/05/msg00006.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20230714-0001
Third Party Advisory