x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative attacks.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 26, 2024 | Mar 21, 2023 |
| Debian | — | Upgrade xen | Mar 27, 2023 | Mar 21, 2023 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Feb 5, 2024 | Mar 21, 2023 |
| Suse | — | Upgrade xenUpgrade xen-libsUpgrade xen-libs-32bitUpgrade xen-toolsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-develUpgrade xen-tools-domUUpgrade xen-doc-html | Mar 22, 2023 | Mar 21, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub