Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.
For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 6, 2024 | May 16, 2024 |
| Debian | — | Upgrade xen | Dec 30, 2024 | May 16, 2024 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Sep 23, 2024 | May 16, 2024 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-libsUpgrade xenUpgrade xen-libs-32bitUpgrade xen-tools-xendomains-wait-diskUpgrade xen-toolsUpgrade xen-develUpgrade xen-tools-domu | Apr 15, 2024 | Apr 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub