CVE-2023-1637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-226 Sensitive Information in Resource Not Removed Before Reuse
Publication date:
27/03/2023
Last modified:
19/02/2025

Description

A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:5.18:rc2:*:*:*:*:*:*