Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.
For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.15.6"
}
]
},
{
"events": [
{
"introduced": "4.16.0"
},
{
"fixed": "4.16.6"
}
]
},
{
"events": [
{
"introduced": "4.17.0"
},
{
"fixed": "4.17.4"
}
]
},
{
"events": [
{
"introduced": "4.18.0"
},
{
"fixed": "4.18.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "40"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31142.json"