CVE-2022-42331

MEDIUM

Xen 4.5.0-4.16.x - Speculative Execution Vulnerability in 32-bit SYSCALL Path

Title source: llm
STIX 2.1

Description

x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative attacks.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 17.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (3)
fedoraproject/fedora 37
fedoraproject/fedora 38
xen/xen 4.5.0 - 4.17.0
Published Mar 21, 2023
Tracked Since Feb 18, 2026