CVE-2023-0045 describes a vulnerability in the Linux kernel's prctl syscall implementation, specifically affecting how speculative execution mitigations are applied. The flaw, present since kernel version 4.9.176, allows for a brief window where previously injected Branch Target Buffer (BTB) values can be exploited before the mitigation is fully active, impacting systems running Debian, Linux, and NetApp products. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and no user interaction required, potentially leading to high confidentiality impacts. The EPSS score is low, indicating a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.16.68, < 3.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.4.180, < 4.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.9.176, < 4.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.14.86, < 4.14.303CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.19.7, < 4.19.270CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.