Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.
For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xen | Xen | * | 4.15.6 (excluding) |
| Xen | Xen | 4.16.0 (including) | 4.16.6 (excluding) |
| Xen | Xen | 4.17.0 (including) | 4.17.4 (excluding) |
| Xen | Xen | 4.18.0 (including) | 4.18.2 (excluding) |
| Xen | Ubuntu | focal | * |
| Xen | Ubuntu | mantic | * |
| Xen | Ubuntu | oracular | * |