CVE-2024-2201

MEDIUM

Linux Kernel < unknown - Info Disclosure

Title source: llm
STIX 2.1

Description

A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.

Scores

CVSS v3 4.7
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
Xen/Xen See advisory "x86: Native Branch History Injection"
Published Dec 19, 2024
Tracked Since Feb 18, 2026