Database/Kernel, userspace & hypervisor

Xen (x86 speculation): Incorrect logic for BTC/SRSO mitigations
CVE-2024-31142Kernel, userspace & hypervisorXSA-455curated
Impact
Incorrect logic for BTC/SRSO mitigations - guests are unprotected against branch-type confusion despite mitigations appearing enabled
Who can reach it
Tenant VM guest
What to do
Hypervisor patch + host reboot. Worth flagging: "mitigation reported as on" was false, so audit rather than trust the sysfs status
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.