Back to Database
Status published
Unknown
CVE-2024-2201
CVE-2024-2201
Vulnerability Description
A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-2201
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.kb.cert.org/vuls/id/155143
- https://github.com/vusec/inspectre-gadget?tab=readme-ov-file
- http://www.openwall.com/lists/oss-security/2024/04/09/15
- http://www.openwall.com/lists/oss-security/2024/05/07/7
- http://xenbits.xen.org/xsa/advisory-456.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QKNCPX7CJUK4I6BRGABAUQK2DMQZUCA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D5OK6MH75S7YWD34EWW7QIZTS627RIE3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RYAZ7P6YFJ2E3FHKAGIKHWS46KYMMTZH/
- https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/branch-history-injection.htm
More from Xen
View All →CVE-2025-58151
varstored: TOCTOU issues with mapped guest memory
Critical
9.4
CVE-2025-58150
x86: buffer overrun with shadow paging + tracing
Unknown
0
CVE-2025-58149
Incorrect removal of permissions on PCI device unplug
Unknown
0
CVE-2025-58148
x86: Incorrect input sanitisation in Viridian hypercalls
Unknown
0
CVE-2025-58147
x86: Incorrect input sanitisation in Viridian hypercalls
Unknown
0
Affected Vendor
Affected Software
Xen
Vulnerable Versions:
See advisory "x86: Native Branch History Injection"
Timeline
Official Publish:
December 19th, 2024
Last Modified:
January 9th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.