CVE-2023-46836
MEDIUMDescription
The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was believed that the mitigations always operated in contexts with IRQs disabled. However, the original XSA-254 fix for Meltdown (XPTI) deliberately left interrupts enabled on two entry paths; one unconditionally, and one conditionally on whether XPTI was active. As BTC/SRSO and Meltdown affect different CPU vendors, the mitigations are not active together by default. Therefore, there is a race condition whereby a malicious PV guest can bypass BTC/SRSO protections and launch a BTC/SRSO attack against Xen.
Is your site exposed to CVE-2023-46836?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| xen | xen |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2023-46836? +
How severe is CVE-2023-46836? +
What products are affected by CVE-2023-46836? +
How do I check if I'm vulnerable to CVE-2023-46836? +
Related Vulnerabilities
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple …
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple …
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple …
For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in …
The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM …
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains parsing …