THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-31142

x86: Incorrect logic for BTC/SRSO mitigations

Reserved:2024-03-28
Published:2024-05-16
Updated:2024-05-16

Description

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html

Product status

Default status
unknown

consult Xen advisory XSA-455
unknown

Credits

This issue was discovered by Andrew Cooper of XenServer. finder

References

https://xenbits.xenproject.org/xsa/advisory-455.html

cve.org CVE-2024-31142

nvd.nist.gov CVE-2024-31142

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-31142