Database/Kernel, userspace & hypervisor

Xen (x86 speculation): Incorrect logic for BTC/SRSO mitigations
CVSS 7.5CVE-2024-31142Kernel, userspace & hypervisorXSA-455curated
Impact
Incorrect logic for BTC/SRSO mitigations - guests are unprotected against branch-type confusion despite mitigations appearing enabled
Who can reach it
Tenant VM guest
What to do
Hypervisor patch + host reboot. Worth flagging: "mitigation reported as on" was false, so audit rather than trust the sysfs status
References
Related entries
- Xen (x86 speculation): Xen hypercall page unsafe against speculative attacks - guest leaks hypervisor memoryCVE-2024-53241 · Xen (x86 speculation)Unscored
- AMD CPU (EntrySign): Improper signature verification in the AMD CPU microcode patch loaderCVE-2024-36347 · AMD CPU (EntrySign)High
- VMware vCenter: Privilege escalation to root on vCenter via a crafted network packetCVE-2024-38813 · VMware vCenterHigh
- Linux kernel NVMe target core (controller teardown racing queue-pair establishment): An initiator that disconnectsCVE-2024-42152 · Linux kernel NVMe target core (controller teardown racing queue-pair establishment)High
- Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure): When command allocation for a new queueCVE-2024-46737 · Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure)High
- Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header isCVE-2024-57791 · Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.