@@ -225,3 +225,10 @@ was never substantiated and was closed as not-a-bug by Red Hat, SUSE and Debian"
# Also in 6.1.150, 6.6.104, 6.12.y and 6.16.5 via the 2025-09-02 stable round.
# The rose/hamradio subsystem was removed entirely in v7.1 (dd8d4bc28ad7).
CVE_STATUS[CVE-2022-1247] = "fixed-version: Fixed from version 6.17"
+
+# "EntryBleed": KPTI maps __entry_text into the user page tables with the
+# global bit set, leaking the KASLR base by prefetch timing. Intel only.
+# Not CVE-2023-3640, which is the separate cpu_entry_area (fixed in v6.2).
+# https://www.willsroot.io/2022/12/entrybleed.html
+CVE_STATUS[CVE-2022-4543] = "upstream-wontfix: no fix planned, KASLR is not \
+considered a defence against local attackers"
KPTI clones the kernel entry text into the user page tables at its KASLR-slid address and, on CPUs with PGE, sets the global bit on those PTEs. The mapping therefore survives the CR3 write on kernel exit, and a local attacker can time prefetch instructions across the kernel range to recover the KASLR base in well under a second. Disclosure and technical write-up: https://www.openwall.com/lists/oss-security/2022/12/16/3 https://www.willsroot.io/2022/12/entrybleed.html The disclosure states that after discussion with security@kernel.org and linux-distros "a fix for this is currently not available", and none has appeared since. arch/x86/mm/pti.c still clones the entry text and still sets _PAGE_GLOBAL on the cloned PTEs as of v7.2, and no commit in mainline references the issue. Debian marks it unimportant with the note "Ignored upstream and KASLR is not expected to be resistant to local attacks": https://security-tracker.debian.org/tracker/CVE-2022-4543 Ubuntu has it deferred since 2023-01-10 with "unfixed upstream", and Red Hat lists current RHEL as Affected with no mitigation available: https://ubuntu.com/security/CVE-2022-4543 https://access.redhat.com/security/cve/CVE-2022-4543 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry area", v6.2) randomizes the CPU entry area, which is CVE-2023-3640. It predates this disclosure and does not address it - the offset of entry_SYSCALL_64 from the KASLR base is unchanged by that commit. CC: Paul Barker <paul@pbarker.dev> AI-Generated: Uses Claude (claude-opus-5) Signed-off-by: Junjie Cao <junjie.cao@linux.dev> --- changes in v2: - split out of the single combined patch, one CVE per patch as requested - added primary source links (disclosures, distribution trackers, mailing list threads, upstream commits) to every commit message - added the three CVEs with no upstream fix as "unpatched" entries instead of leaving them undocumented - disclosed AI assistance per the contributor guide v1: https://lore.kernel.org/openembedded-core/20260802143444.1178575-1-junjie.cao@linux.dev/ meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++ 1 file changed, 7 insertions(+)