CVE-2023-1637 affects Linux kernel x86 power management: after a suspend-to-RAM (S3) resume, the boot CPU may fail to restore model-specific registers (MSRs) that control speculative-execution mitigations. Secondary CPUs restore the relevant state through identify_secondary_cpu(), but the boot CPU can resume without the intended protections, enabling a local authenticated attacker to potentially access CPU memory and creating a high confidentiality impact.
The upstream fix saves and restores Intel and AMD speculation-control MSRs through pm_save_spec_msr() during processor-state restoration and was designated for stable-kernel backports. Red Hat rated the issue moderate (CVSS 3.1 5.5; AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) and released corrected kernel and kernel-rt packages for affected RHEL 8 and RHEL 9 streams; Fedora had addressed it in stable 5.16.20 kernel updates.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:5244 for the RHEL 8 kernel and RHSA-2023:5255 for RHEL 8 kernel-rt, fixing the S3-resume speculative-MSR flaw.
Red Hat issued RHSA-2023:5069 and RHSA-2023:5091 to remediate CVE-2023-1637 in RHEL 9 kernel and kernel-rt packages.
Red Hat released RHSA-2023:4789 to fix affected kernel packages for RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
Pawan Gupta authored a Linux kernel patch to save and restore speculation-related MSRs during suspend-to-RAM resume, addressing missing boot-CPU mitigation state after S3 resume.
Red Hat issued RHSA-2023:5794 to remediate CVE-2023-1637 in the RHEL 8.4 Telecommunications Update Service kernel-rt package.
RHSA-2023:5628 fixed CVE-2023-1637 in RHEL 8.4 Advanced Mission Critical Update Support, Update Services for SAP Solutions, and Telecommunications Update Service kernel packages.
Linus Torvalds committed e2a1256b17b16f9b9adf1b6fea56819e7b68e463, adding pm_save_spec_msr() to preserve and restore Intel and AMD speculation-control MSRs during S3 resume. The patch was marked for stable-kernel consideration.
glibc committed 1e000d3d33211d5a954300e2a69b90f93f18a1a1 to blacklist additional Intel CPUs for TSX handling, including model 0x8e stepping 0x0c, disabling TSX and enabling RTM_ALWAYS_ABORT. The change fixed the observed glibc feature-test failures and was included in glibc 2.35 and backported to older release branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcesourceware.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.