diff mbox series

[v2,06/10] cve-exclusion: set status for CVE-2022-4543

Message ID 20260803084827.1348810-7-junjie.cao@linux.dev
State New
Headers show
Series cve-exclusion: triage ten kernel CVEs lacking upstream fix data | expand

Commit Message

Junjie Cao Aug. 3, 2026, 8:48 a.m. UTC
KPTI clones the kernel entry text into the user page tables at its
KASLR-slid address and, on CPUs with PGE, sets the global bit on those
PTEs. The mapping therefore survives the CR3 write on kernel exit, and a
local attacker can time prefetch instructions across the kernel range to
recover the KASLR base in well under a second.

Disclosure and technical write-up:

  https://www.openwall.com/lists/oss-security/2022/12/16/3
  https://www.willsroot.io/2022/12/entrybleed.html

The disclosure states that after discussion with security@kernel.org and
linux-distros "a fix for this is currently not available", and none has
appeared since. arch/x86/mm/pti.c still clones the entry text and still
sets _PAGE_GLOBAL on the cloned PTEs as of v7.2, and no commit in
mainline references the issue.

Debian marks it unimportant with the note "Ignored upstream and KASLR is
not expected to be resistant to local attacks":

  https://security-tracker.debian.org/tracker/CVE-2022-4543

Ubuntu has it deferred since 2023-01-10 with "unfixed upstream", and
Red Hat lists current RHEL as Affected with no mitigation available:

  https://ubuntu.com/security/CVE-2022-4543
  https://access.redhat.com/security/cve/CVE-2022-4543

97e3d26b5e5f ("x86/mm: Randomize per-cpu entry area", v6.2) randomizes
the CPU entry area, which is CVE-2023-3640. It predates this disclosure
and does not address it - the offset of entry_SYSCALL_64 from the KASLR
base is unchanged by that commit.

CC: Paul Barker <paul@pbarker.dev>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
changes in v2:
- split out of the single combined patch, one CVE per patch as requested
- added primary source links (disclosures, distribution trackers, mailing
  list threads, upstream commits) to every commit message
- added the three CVEs with no upstream fix as "unpatched" entries instead
  of leaving them undocumented
- disclosed AI assistance per the contributor guide

v1: https://lore.kernel.org/openembedded-core/20260802143444.1178575-1-junjie.cao@linux.dev/

 meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
 1 file changed, 7 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index 7547cdfd..3517318e 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -225,3 +225,10 @@  was never substantiated and was closed as not-a-bug by Red Hat, SUSE and Debian"
 # Also in 6.1.150, 6.6.104, 6.12.y and 6.16.5 via the 2025-09-02 stable round.
 # The rose/hamradio subsystem was removed entirely in v7.1 (dd8d4bc28ad7).
 CVE_STATUS[CVE-2022-1247] = "fixed-version: Fixed from version 6.17"
+
+# "EntryBleed": KPTI maps __entry_text into the user page tables with the
+# global bit set, leaking the KASLR base by prefetch timing. Intel only.
+# Not CVE-2023-3640, which is the separate cpu_entry_area (fixed in v6.2).
+# https://www.willsroot.io/2022/12/entrybleed.html
+CVE_STATUS[CVE-2022-4543] = "upstream-wontfix: no fix planned, KASLR is not \
+considered a defence against local attackers"