CVE-2023-0597 affects the Linux kernel’s x86 CPU-entry-area mapping, whose per-CPU structures were mapped into userspace page tables for Kernel Page-Table Isolation (KPTI) at predictable locations despite KASLR. A local low-privileged attacker could use this predictability to infer the locations of exception stacks or other sensitive kernel memory and potentially obtain unauthorized access; Red Hat rated the issue 7.0 CVSS v3.1 and noted exploitation could enable a complex arbitrary-write primitive.
The upstream mitigation randomizes the placement of per-CPU CPU-entry-area structures on x86_64, assigning each possible CPU a unique randomized offset within the 512 GB P4D virtual-address region reserved for that area while retaining the existing x86_32 layout. Red Hat released fixed kernels for supported RHEL 8 and RHEL 9 streams and Red Hat Virtualization 4 on RHEL 8; RHEL 6 is unaffected, while RHEL 7 is outside support scope.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:6901 for RHEL 8 kernel-rt and RHSA-2023:7077 for the RHEL 8 kernel, addressing CVE-2023-0597.
Red Hat issued RHSA-2023:6583 to fix CVE-2023-0597 in the Red Hat Enterprise Linux 9 kernel.
Peter Zijlstra submitted an x86_64 Linux kernel patch to randomize per-CPU CPU-entry-area placements after Seth Jenkins reported that the mapping remained predictable despite KASLR. The change assigns unique randomized offsets to CPU entry areas mapped for KPTI.
Red Hat issued RHSA-2024:10772 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:10773 for its kernel-rt package, fixing CVE-2023-0597.
Red Hat issued RHSA-2024:10262 to address CVE-2023-0597 in the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
RHSA-2024:1188 fixed CVE-2023-0597 for the RHEL 8.6 Extended Update Support kernel and the Red Hat Virtualization 4 for RHEL 8 kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.