VDB

DEBIAN-CVE-2023-3640

DEBIAN-CVE-2023-3640 PUBLISHED CVSS 7.800000190734863 HIGH

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13linux0, *, 6.17.8-1
Debian:11linux*, 6.1.119-1, 6.1.12-1
Debian:14linux*, 6.12.57-1, *
Debian:12linux6.12.13-1, 6.12.15-1, 6.12.16-1

Exploit Intelligence

Timeline

  • Jul 24, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›