EntryBleed (CVE-2022-4543) is a vulnerability in the Linux Kernel's Page Table Isolation (KPTI) implementation. On Intel systems, a local attacker can exploit prefetch side-channels based on TLB timing to leak the Kernel Address Space Layout Randomization (KASLR) base address. The flaw arises from the way KPTI manages page table entries, allowing timing differences to be observed and used to infer kernel memory layout.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a local Linux kernel exploitation research environment rather than a remote exploit. Its purpose is to build a minimal QEMU VM and run proof-of-concept side-channel binaries that leak kernel address layout information from user space. Structure: - pwn/entry.c: standalone C PoC that scans canonical kernel text address ranges in 2 MB steps, using rdtscp timing around prefetchnta/prefetcht2 and repeated SYS_getuid calls. It identifies the lowest-latency candidate near the syscall entry offset and derives a probable kernel text base. This is effectively a KASLR derandomization primitive. - pwn/physmap.c: larger C PoC that scans candidate physmap/direct-map bases and TSS-related offsets. It measures timing repeatedly, performs coarse candidate selection, then iterative refinement with qsort ranking until one best base remains. It also reads /sys/firmware/memmap to estimate RAM extent and narrow the search space. This is another address disclosure primitive aimed at recovering the physmap base. - pwn/physmap_test/Makefile: helper for building a kernel module test artifact, likely for experimentation; the actual module source is not present in the provided content. - qemu/: VM lab scaffolding. Dockerfiles and scripts build a Linux kernel and static BusyBox from source archives placed in qemu/src. kernel.fragment enables debugging, KASLR-related options, PTI, symbols, and virtio support. qemu/init mounts proc/sys/dev/tmpfs, disables kptr_restrict, prints kallsyms, and drops into a shell. - build.sh: orchestrates Docker-based kernel, BusyBox, and initramfs builds. - run.sh: compiles the pwn/*.c binaries statically with musl-gcc and contains a commented QEMU launch line plus optional GDB integration. Boot flags allow toggling KASLR, SMEP, SMAP, PTI, and root shell behavior. Capabilities: - Local microarchitectural side-channel probing of kernel virtual addresses. - Leakage of probable kernel text base from user mode. - Leakage of probable physmap/direct-map base from user mode. - Support tooling for reproducible VM-based kernel exploit development and debugging. There are no network exploitation routines, C2 callbacks, or weaponized payloads. The repository does not itself escalate privileges; instead it provides information leaks that would be useful as prerequisites for a later kernel privilege-escalation exploit.
This repository provides a proof-of-concept (PoC) exploit for CVE-2022-4543, targeting the Linux kernel. The exploit consists of two main files: dekaslr.c and main.cpp. The dekaslr.c file implements a side-channel timing attack to probe kernel memory and deduce the kernel base address, effectively bypassing Kernel Address Space Layout Randomization (KASLR). The main.cpp file acts as a wrapper, automating multiple runs of the dekaslr binary and statistically determining the most frequent kernel base address. The exploit is intended for local execution on a vulnerable Linux system and does not require network access. The repository is structured for easy compilation and usage, with clear instructions in the README. No hardcoded IPs, URLs, or network endpoints are present; the only fingerprintable endpoint is the path to the dekaslr binary. The exploit is a PoC and does not provide a weaponized payload, but it is a valuable tool for further kernel exploitation by revealing the kernel base address.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.