CVE-2024-2193
published 2024-03-15CVE-2024-2193: A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been…
PriorityP337medium5.7CVSS 3.1
AVLACHPRHUINSUCHIHAN
EPSS
1.23%
65.6th percentile
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | cpu | — | — |
| debian | linux | < xen 4.17.5+23-ga4e5191dc0-1 (bookworm) | xen 4.17.5+23-ga4e5191dc0-1 (bookworm) |
| debian | xen | < xen 4.17.5+23-ga4e5191dc0-1 (bookworm) | xen 4.17.5+23-ga4e5191dc0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.17.5+23-ga4e5191dc0-1 | 4.17.5+23-ga4e5191dc0-1 |
| xen | xen | >= 0 < 4.19.1-1 | 4.19.1-1 |
| xen | xen | >= 0 < 4.19.1-1 | 4.19.1-1 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
osv5.7MEDIUM
vendor_redhat7.5HIGH
vendor_debian5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-2193: A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has be
osv·2024-03-15·CVSS 5.7
CVE-2024-2193 [MEDIUM] CVE-2024-2193: A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has be
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.
GHSA
GHSA-3p53-237x-3cww: A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has be
ghsa_unreviewed·2024-03-15
CVE-2024-2193 [MEDIUM] CWE-362 GHSA-3p53-237x-3cww: A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has be
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.
Red Hat
postgresql: PostgreSQL row security below e.g. subqueries disregards user ID changes
vendor_redhat·2024-11-14·CVSS 7.5
CVE-2024-10976 [HIGH] CWE-1250 postgresql: PostgreSQL row security below e.g. subqueries disregards user ID changes
postgresql: PostgreSQL row security below e.g. subqueries disregards user ID changes
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a commo
Red Hat
hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision timers, etc)
vendor_redhat·2024-03-12·CVSS 5.7
CVE-2024-2193 [MEDIUM] CWE-1300 hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision timers, etc)
hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision timers, etc)
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.
A new cache speculation vulnerability, known as Spectre-SRC (Speculative Race Conditions), was found in hw. Spectre-SRC is similar to the Spectre v1 and allows speculative use-after-free. The difference between this issue and Spectre V1 is that this issue is based
Debian
CVE-2024-2193: linux - A Speculative Race Condition (SRC) vulnerability that impacts modern CPU archite...
vendor_debian·2024·CVSS 5.7
CVE-2024-2193 [MEDIUM] CVE-2024-2193: linux - A Speculative Race Condition (SRC) vulnerability that impacts modern CPU archite...
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-2193 hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision
bugzilla·2024-01-31·CVSS 5.7
CVE-2024-2193 [MEDIUM] CVE-2024-2193 hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision
CVE-2024-2193 hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision timers, etc)
Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision timers, etc). In this flaw, all the common synchronization primitives can be microarchitecturally bypassed on speculative paths, turning all architecturally race-free critical regions into Speculative Race Conditions (SRCs).
The goal of a GhostRace attack is to disclose arbitrary kernel data by exploiting a speculative race condition in an otherwise architecturally race-free critical region
Reference:
https://www.ope
Talos
Not everything has to be a massive, global cyber attack
blogs_talos·2024-03-14
Not everything has to be a massive, global cyber attack
Some of my Webex rooms recently have been blowing up with memes about blaming Canada or wild speculation that a state-sponsored actor is carrying out some sort of major campaign.
After a widespread outage of cellular service with AT&T and other carriers a few weeks ago, people were sure it was some sort of coordinated attack to disrupt Americans’ services that largely power our day-to-day lives. The outage lasted about 11 hours, and after the fact, the company announced they’d give customers a whopping $5 credit to make up for the issue. The Federal Communications Commission also announced last week that it was launching a formal investigation into the outage, requesting more information about the exact cause and how many users were affected.
About two weeks later, the same kinds of mess
Talos
Not everything has to be a massive, global cyber attack
blogs_talos·2024-03-14
Not everything has to be a massive, global cyber attack
## Not everything has to be a massive, global cyber attack
Some of my Webex rooms recently have been blowing up with memes about blaming Canada or wild speculation that a state-sponsored actor is carrying out some sort of major campaign.
After a widespread outage of cellular service with AT&T and other carriers a few weeks ago, people were sure it was some sort of coordinated attack to disrupt Americans’ services that largely power our day-to-day lives. The outage lasted about 11 hours, and after the fact, the company announced they’d give customers a whopping $5 credit to make up for the issue. The Federal Communications Commission also announced last week that it was launching a formal investigation into the outage, requesting more information about the exact cause and how many users w
http://www.openwall.com/lists/oss-security/2024/03/12/14https://download.vusec.net/papers/ghostrace_sec24.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=944d5fe50f3f03daacfea16300e656a1691c4a23https://ibm.github.io/system-security-research-updates/2024/03/12/ghostracehttps://kb.cert.org/vuls/id/488902https://lists.fedoraproject.org/archives/list/[email protected]/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK/https://lists.fedoraproject.org/archives/list/[email protected]/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A/https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7016.htmlhttps://www.kb.cert.org/vuls/id/488902https://www.vusec.net/projects/ghostrace/https://xenbits.xen.org/xsa/advisory-453.htmlhttp://www.openwall.com/lists/oss-security/2024/03/12/14http://xenbits.xen.org/xsa/advisory-453.htmlhttps://download.vusec.net/papers/ghostrace_sec24.pdfhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=944d5fe50f3f03daacfea16300e656a1691c4a23https://ibm.github.io/system-security-research-updates/2024/03/12/ghostracehttps://kb.cert.org/vuls/id/488902https://lists.fedoraproject.org/archives/list/[email protected]/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK/https://lists.fedoraproject.org/archives/list/[email protected]/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A/https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7016.htmlhttps://www.kb.cert.org/vuls/id/488902https://www.vusec.net/projects/ghostrace/https://xenbits.xen.org/xsa/advisory-453.html
2024-03-15
Published