We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-31142

x86: Incorrect logic for BTC/SRSO mitigations



AssignerXEN
Reserved2024-03-28
Published2024-05-16
Updated2024-08-02

Description

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html

Product status

Default status
unknown

consult Xen advisory XSA-455
unknown

Credits

This issue was discovered by Andrew Cooper of XenServer. 0x40059e7d20

References

https://xenbits.xenproject.org/xsa/advisory-455.html

cve.org CVE-2024-31142

nvd.nist.gov CVE-2024-31142

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.