CVE-2024-31142

Severity CVSS v4.0:
Pending analysis
Type:
CWE-693 Protection Mechanism Failure
Publication date:
16/05/2024
Last modified:
05/01/2026

Description

Because of a logical error in XSA-407 (Branch Type Confusion), the<br /> mitigation is not applied properly when it is intended to be used.<br /> XSA-434 (Speculative Return Stack Overflow) uses the same<br /> infrastructure, so is equally impacted.<br /> <br /> For more details, see:<br /> https://xenbits.xen.org/xsa/advisory-407.html<br /> https://xenbits.xen.org/xsa/advisory-434.html<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* 4.15.6 (excluding)
cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* 4.16.0 (including) 4.16.6 (excluding)
cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* 4.17.0 (including) 4.17.4 (excluding)
cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* 4.18.0 (including) 4.18.2 (excluding)
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*