Wiz Agents & Workflows are here

CVE-2023-1998
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-1998 is a vulnerability in the Linux Kernel affecting Spectre v2 SMT mitigations. The issue was discovered when it was found that on VMs of major cloud providers, the kernel still left victim processes exposed to attacks in some cases even after enabling the spectre-BTI mitigation with prctl. The vulnerability was reported on February 20, 2023 and fixed on March 10, 2023 (GitHub Security).

Technical details

The vulnerability occurs when plain IBRS (not enhanced IBRS) is enabled. The kernel's logic determined that STIBP was not needed since IBRS bit implicitly protects against cross-thread branch target injection. However, with legacy IBRS, the IBRS bit was cleared on returning to userspace for performance reasons, which disabled the implicit STIBP protection and left userspace threads vulnerable to cross-thread branch target injection (Linux Commit).

Impact

The vulnerability could allow a local or remote attacker to leak sensitive information from user-space applications that attempt to enable Spectre v2 mitigations. This particularly affects systems using legacy IBRS without enhanced IBRS support (Red Hat Portal).

Mitigation and workarounds

The issue was fixed in Linux kernel 6.3 by modifying the spectre_v2_user_select_mitigation() function to allow enabling STIBP with legacy IBRS. The fix excludes IBRS from the spectre_v2_in_ibrs_mode() check to allow for enabling STIBP through seccomp/prctl() by default or always-on if selected by spectre_v2_user kernel cmdline parameter (Linux Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23395CRITICAL9.1
  • Linux KernelLinux Kernel
  • linux-xilinx-zynqmp
NoYesMar 25, 2026
CVE-2026-23399MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoYesMar 28, 2026
CVE-2026-23398MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-abi-stablelists
NoYesMar 26, 2026
CVE-2026-23397MEDIUM4.4
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesMar 26, 2026
CVE-2026-31788N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel-matched
NoYesMar 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management