Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40795
HistoryJun 05, 2023 - 8:42 p.m.

Thread Counter Overflow

2023-06-0520:42:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
xen
vulnerability
thread counter
overflow
amd
software
ssbd
selection
mishandling

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS

0

Percentile

9.0%

Xen is vulnerable to a Thread Counter Overflow. The vulnerability arises from the mishandling of guest SSBD (Speculative Store Bypass Disable) selection on AMD hardware. This mishandling enables a guest to underflow or overflow the thread counter. Each write to VIRT_SPEC_CTRL.SSBD by the guest is propagated to the helper responsible for per-core active accounting. Underflowing the counter can cause the value to become saturated

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS

0

Percentile

9.0%