CVE-2023-0597 affects the Linux kernel's x86 cpu_entry_area mapping. Before Linux 6.2, the per-CPU entry area occupied a fixed, predictable kernel virtual address, allowing local users to locate exception stacks and other important kernel data. User-controlled register state saved through the SP0 entry stack and pt_regs could also occupy predictable kernel-space locations, facilitating forged kernel structures or ROP-chain placement. Linux 6.2 introduced cea_offset to randomize the per-CPU entry-area offset relative to the IDT when KASLR is enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel information-disclosure vulnerability involving x86 cpu_entry_area mappings. A local user with low privileges could predict sensitive memory locations and access important data. The reference assigns a CVSS v3 base score of 5.5, with confidentiality impact but no stated integrity or availability impact. The prescribed fix is to update the Echo linux package and related packages to version 6.3.7-1 or later.
Linux kernel x86 memory-management issue addressed by randomizing the per-CPU entry area.
Linux kernel x86 per-CPU entry-area randomization issue.
Linux kernel x86 memory issue involving per-CPU entry-area randomization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.