Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-46836
HistoryJan 05, 2024 - 5:15 p.m.

Type confusion

2024-01-0517:15:00
PRIOn knowledge base
www.prio-n.com
3
type confusion
xsa-422
branch type confusion
xsa-434
speculative return stack overflow
irq-safe
xsa-254 fix
meltdown
xpti
cpu vendors
race condition
malicious pv guest
xen
nvd

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative
Return Stack Overflow) are not IRQ-safe. It was believed that the
mitigations always operated in contexts with IRQs disabled.

However, the original XSA-254 fix for Meltdown (XPTI) deliberately left
interrupts enabled on two entry paths; one unconditionally, and one
conditionally on whether XPTI was active.

As BTC/SRSO and Meltdown affect different CPU vendors, the mitigations
are not active together by default. Therefore, there is a race
condition whereby a malicious PV guest can bypass BTC/SRSO protections
and launch a BTC/SRSO attack against Xen.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%