QID 355312

Date Published: 2023-05-29

QID 355312: Amazon Linux Security Advisory for kernel : ALAS2023-2023-127

A regression exists in the linux kernel within kvm: nvmx that allowed for speculative execution attacks.
L2 can carry out spectre v2 attacks on l1 due to l1 thinking it doesn't need retpolines or ibpb after running l2 due to kvm (l0) advertising eibrs support to l1.
An attacker at l2 with code execution can execute code on an indirect branch on the host machine.
We recommend upgrading to kernel 6.2 or past commit 2e7eab81425a (cve-2022-2196) in the linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. (
( CVE-2023-26545)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2023-127 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 355312

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2023-127 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-127.html