CVE-2022-42331
21.03.2023, 13:15
x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative attacks.Enginsight
Vendor | Product | Version |
---|---|---|
xen | xen | 4.5.0 ≤ 𝑥 ≤ 4.17.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References