cbcvebase.
CVE-2024-31143
published 2024-07-18

CVE-2024-31143: An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of…

PriorityP340high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.51%
39.9th percentile
An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling an error path could be taken in different situations, with or without a particular lock held. This error path wrongly releases the lock even when it is not currently held.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.17.5+23-ga4e5191dc0-1 (bookworm)xen 4.17.5+23-ga4e5191dc0-1 (bookworm)
xenxen>= 0 < 4.16.6-r14.16.6-r1
xenxen>= 0 < 4.17.5-r04.17.5-r0
xenxen>= 0 < 4.18.3-r04.18.3-r0
xenxen>= 0 < 4.18.3-r04.18.3-r0
xenxen>= 0 < 4.19.0-r04.19.0-r0
xenxen>= 0 < 4.19.0-r04.19.0-r0
xenxen>= 0 < 4.19.0-r04.19.0-r0
xenxen>= 0 < 4.17.5+23-ga4e5191dc0-14.17.5+23-ga4e5191dc0-1
xenxen>= 0 < 4.19.1-14.19.1-1
xenxen>= 0 < 4.19.1-14.19.1-1
xenxen>= 4.4.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.