Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.
For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 6, 2024 | May 16, 2024 |
| Debian | — | Upgrade xen | Dec 30, 2024 | May 16, 2024 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Sep 23, 2024 | May 16, 2024 |
| Suse | — | Upgrade xen-tools-xendomains-wait-diskUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xenUpgrade xen-doc-htmlUpgrade xen-develUpgrade xen-tools-domuUpgrade xen-tools | Apr 15, 2024 | Apr 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub