Description
A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.
Published: 2024-12-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-5658-1 linux security update
Debian DSA Debian DSA DSA-5836-1 xen security update
Ubuntu USN Ubuntu USN USN-6766-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6766-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6766-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-6774-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6795-1 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6828-1 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6865-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6866-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6866-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-6866-3 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-6868-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6868-2 Linux kernel (AWS) vulnerabilities
History

Thu, 09 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 20:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in some Intel CPUs where mitigations for the Spectre V2/BHI vulnerability were incomplete. This issue may allow an attacker to read arbitrary memory, compromising system integrity and exposing sensitive information. A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.
Title hw: cpu: intel: Native Branch History Injection (BHI) CVE-2024-2201
References

Wed, 30 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_eus:9.2
cpe:/a:redhat:rhel_eus:9.2::nfv
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat rhel Eus

Thu, 10 Oct 2024 02:45:00 +0000


Tue, 24 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els

Tue, 24 Sep 2024 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Extras Rt Els
CPEs cpe:/a:redhat:rhel_extras_rt_els:7
Vendors & Products Redhat rhel Extras Rt Els

Thu, 08 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8::nfv
cpe:/o:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

Subscriptions

Redhat Enterprise Linux Rhel Els Rhel Eus Rhel Extras Rt Els
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-01-09T16:40:32.522Z

Reserved: 2024-03-05T19:12:39.649Z

Link: CVE-2024-2201

cve-icon Vulnrichment

Updated: 2024-12-31T18:54:45.666Z

cve-icon NVD

Status : Deferred

Published: 2024-12-19T21:15:08.103

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-2201

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-09T04:30:00Z

Links: CVE-2024-2201 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses