CVE-2023-46836
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/01/2024
Last modified:
03/06/2025
Description
The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative<br />
Return Stack Overflow) are not IRQ-safe. It was believed that the<br />
mitigations always operated in contexts with IRQs disabled.<br />
<br />
However, the original XSA-254 fix for Meltdown (XPTI) deliberately left<br />
interrupts enabled on two entry paths; one unconditionally, and one<br />
conditionally on whether XPTI was active.<br />
<br />
As BTC/SRSO and Meltdown affect different CPU vendors, the mitigations<br />
are not active together by default. Therefore, there is a race<br />
condition whereby a malicious PV guest can bypass BTC/SRSO protections<br />
and launch a BTC/SRSO attack against Xen.<br />
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page