CVE Vulnerabilities

CVE-2024-31142

Protection Mechanism Failure

Published: May 16, 2024 | Modified: Jan 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.

For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

Name Vendor Start Version End Version
Xen Xen * 4.15.6 (excluding)
Xen Xen 4.16.0 (including) 4.16.6 (excluding)
Xen Xen 4.17.0 (including) 4.17.4 (excluding)
Xen Xen 4.18.0 (including) 4.18.2 (excluding)
Xen Ubuntu focal *
Xen Ubuntu mantic *
Xen Ubuntu oracular *

References