CVE-2024-31142
16.05.2024, 14:15
Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.htmlEnginsight
| Vendor | Product | Version |
|---|---|---|
| xen | xen | 𝑥 < 4.15.6 |
| xen | xen | 4.16.0 ≤ 𝑥 < 4.16.6 |
| xen | xen | 4.17.0 ≤ 𝑥 < 4.17.4 |
| xen | xen | 4.18.0 ≤ 𝑥 < 4.18.2 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xen |
|
Ubuntu Releases
Common Weakness Enumeration
References