CVE-2023-0045 is an incomplete speculative-execution mitigation in the Linux kernel's conditional Indirect Branch Prediction Barrier (IBPB) support controlled through the prctl system call. The ib_prctl_set function updates task Thread Information Flags and the SPEC_CTRL MSR, but does not immediately issue an IBPB. Instead, the barrier is deferred until a subsequent scheduling event. Consequently, branch-target-buffer values injected before the prctl call remain available to speculative execution during the intervening period.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) demonstrating a local Spectre-BTI (Branch Target Injection) attack that bypasses user-space mitigations (prctl and seccomp) on Linux. The exploit is structured into several C source files, scripts, and helper files: - The core PoC is in 'poc_files/attacker.c' (attacker process) and 'poc_files/victim.c' (victim process), both using shared code from 'poc_files/common.h'. The attacker and victim are run concurrently, with CPU affinity set to maximize the attack's reliability. - The victim loads a secret from 'secret.txt' and attempts to protect itself using prctl or seccomp mitigations. However, due to a window in the Linux kernel's implementation, the attacker can still leak bits of the secret using a Flush+Reload cache side-channel. - The attack is orchestrated by 'poc_files/poc.sh', which automates the process of running the attacker and victim, collecting results in 'result.txt', and parsing the leaked secret with 'parseResult.py'. - Additional files like 'test.c' and 'utils.h' provide further testing and utility functions for speculative execution and cache probing. The exploit demonstrates that the current Linux kernel mitigations for Spectre-BTI are insufficient, as there is a period after the mitigation syscall where the process remains vulnerable. The PoC is intended for research and demonstration purposes, highlighting the need for improved kernel-level mitigations. The attack is local and requires the ability to run code on the target system, but does not require elevated privileges.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel speculative-execution mitigation flaw in conditional IBPB handling via prctl, leaving an interval in which previously injected branch-target-buffer values may affect a victim.
Vulnerability addressed by the AlmaLinux 9.2 TuxCare advisory.
A vulnerability included in the TuxCare AlmaLinux 9.2 kernel security update advisory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.