cbcvebase.
CVE-2024-2193
published 2024-03-15

CVE-2024-2193: A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been…

PriorityP337medium5.7CVSS 3.1
AVLACHPRHUINSUCHIHAN
EPSS
1.23%
65.6th percentile
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.

Affected

7 ranges
VendorProductVersion rangeFixed in
amdcpu
debianlinux< xen 4.17.5+23-ga4e5191dc0-1 (bookworm)xen 4.17.5+23-ga4e5191dc0-1 (bookworm)
debianxen< xen 4.17.5+23-ga4e5191dc0-1 (bookworm)xen 4.17.5+23-ga4e5191dc0-1 (bookworm)
xenxen
xenxen>= 0 < 4.17.5+23-ga4e5191dc0-14.17.5+23-ga4e5191dc0-1
xenxen>= 0 < 4.19.1-14.19.1-1
xenxen>= 0 < 4.19.1-14.19.1-1

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
osv5.7MEDIUM
vendor_redhat7.5HIGH
vendor_debian5.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.