CVE-2019-1125, commonly called Spectre SWAPGS, is a Spectre Variant 1-like speculative-execution information-disclosure vulnerability affecting kernel entry handling on x86-64 systems with Intel or AMD processors. Conditional branches governing the SWAPGS instruction can be mispredicted during transitions into kernel code. Dependent operations may transiently use an incorrect GS-register value, allowing microarchitectural state changes to expose privileged memory through a timing side channel. The issue affects Linux kernel system-call and interrupt-entry paths and was also addressed as a Windows kernel information-disclosure vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept (PoC) exploit for the SWAPGS speculative execution vulnerability (CVE-2019-1125), as presented at Black Hat USA 2019. The exploit is implemented in C and x64 assembly, with two main variants: 'leakgsbkva' and 'leakgsbkvat', each in its own Visual Studio solution and project directory. Both variants attempt to leak values from kernel memory (specifically, the PE header of the Windows kernel image) into user space by abusing speculative execution and branch prediction confusion, targeting the SWAPGS instruction. The code allocates user-mode buffers at specific addresses, manipulates CPU state (GS base), and measures cache access times to infer leaked kernel values. The exploit is a local PoC and does not provide a weaponized payload, but demonstrates the feasibility of leaking kernel memory on unpatched Windows x64 systems. The repository is well-structured, with clear separation between the two PoC variants, and includes both C and assembly source files, as well as Visual Studio project files for building the PoCs. No network or remote endpoints are involved; the attack is purely local and targets the system's own kernel memory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spectre SWAPGS speculative-execution gadget vulnerability in the Linux kernel.
A hardware-side-channel vulnerability involving a Spectre SWAPGS gadget in the Linux kernel.
A hardware-related Linux kernel Spectre SWAPGS gadget vulnerability.
A Linux kernel hardware-side-channel vulnerability involving a Spectre SWAPGS gadget.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.