CVE Vulnerabilities

CVE-2024-31142

Protection Mechanism Failure

Published: May 16, 2024 | Modified: Jan 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.

For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
XenXen*4.15.6 (excluding)
XenXen4.16.0 (including)4.16.6 (excluding)
XenXen4.17.0 (including)4.17.4 (excluding)
XenXen4.18.0 (including)4.18.2 (excluding)
XenUbuntufocal*
XenUbuntumantic*
XenUbuntuoracular*
XenUbuntuplucky*

References