CVE-2023-46836

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/01/2024
Last modified:
03/06/2025

Description

The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative<br /> Return Stack Overflow) are not IRQ-safe. It was believed that the<br /> mitigations always operated in contexts with IRQs disabled.<br /> <br /> However, the original XSA-254 fix for Meltdown (XPTI) deliberately left<br /> interrupts enabled on two entry paths; one unconditionally, and one<br /> conditionally on whether XPTI was active.<br /> <br /> As BTC/SRSO and Meltdown affect different CPU vendors, the mitigations<br /> are not active together by default. Therefore, there is a race<br /> condition whereby a malicious PV guest can bypass BTC/SRSO protections<br /> and launch a BTC/SRSO attack against Xen.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*