CVE-2024-31145
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
25/09/2024
Last modified:
05/01/2026
Description
Certain PCI devices in a system might be assigned Reserved Memory<br />
Regions (specified via Reserved Memory Region Reporting, "RMRR") for<br />
Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used<br />
for platform tasks such as legacy USB emulation.<br />
<br />
Since the precise purpose of these regions is unknown, once a device<br />
associated with such a region is active, the mappings of these regions<br />
need to remain continuouly accessible by the device. In the logic<br />
establishing these mappings, error handling was flawed, resulting in<br />
such mappings to potentially remain in place when they should have been<br />
removed again. Respective guests would then gain access to memory<br />
regions which they aren&#39;t supposed to have access to.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* | 4.0.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



