GPU VulnDB

Database/Kernel, userspace & hypervisor

Xen (x86 speculation): Incorrect logic for BTC/SRSO mitigations

CVSS 7.5CVE-2024-31142Kernel, userspace & hypervisorXSA-455curated

Impact

Incorrect logic for BTC/SRSO mitigations - guests are unprotected against branch-type confusion despite mitigations appearing enabled

Who can reach it

Tenant VM guest

What to do

Hypervisor patch + host reboot. Worth flagging: "mitigation reported as on" was false, so audit rather than trust the sysfs status

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.