Race condition in Xen - CVE-2024-2193
Published: March 12, 2024 / Updated: September 13, 2024
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a speculative race condition. A local user can exploit the race and gain unauthorized access to contents of arbitrary host memory, including memory assigned to other guests.
The vulnerability was dubbed GhostRace.
Affected software
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
F5OS
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
openSUSE Leap
Fedora
Traffix SDC
BIG-IP
BIG-IP Next Central Manager
xen-devel
xen-libs-32bit
xen-tools-domU
xen-libs-debuginfo-32bit
xen-tools-debuginfo
xen-libs
xen-debugsource
xen
xen-tools-domU-debuginfo
xen-doc-html
xen-tools
xen-libs-debuginfo
xen-tools-xendomains-wait-disk
xen-libs-32bit-debuginfo
xen-libs-64bit-debuginfo
xen-libs-64bit
app-emulation/xen
xen (Debian package)
kernel
EMC Cloud Tiering Appliance
How to mitigate CVE-2024-2193
xen-devel - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-libs-32bit - addressed in versions 4.12.4_46-3.106.1, 4.14.6_12-150300.3.69.1
xen-tools-domU - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-libs-debuginfo-32bit - update to 4.12.4_46-3.106.1
xen-tools-debuginfo - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-libs - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-debugsource - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-tools-domU-debuginfo - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-doc-html - addressed in versions 4.12.4_46-3.106.1, 4.14.6_12-150300.3.69.1
xen-tools - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-libs-debuginfo - addressed in versions 4.12.4_46-3.106.1, 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-tools-xendomains-wait-disk - addressed in versions 4.13.5_12-150200.3.93.1, 4.14.6_12-150300.3.69.1
xen-libs-32bit-debuginfo - update to 4.14.6_12-150300.3.69.1
xen-libs-64bit-debuginfo - update to 4.14.6_12-150300.3.69.1
xen-libs-64bit - update to 4.14.6_12-150300.3.69.1
xen - addressed in versions 4.17.2-8.fc38, 4.17.2-8.fc39, 4.18.0-7.fc40, 4.18.1-1.fc40
app-emulation/xen - update to 4.17.4
xen (Debian package) - update to 4.17.5+23-ga4e5191dc0-1
kernel - update to 6.1.79-99.164
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
External References
Related Security Bulletins
- Speculative race condition aka GhostRace in Xen
- Fedora 40 update for xen
- Fedora 39 update for xen
- Fedora 38 update for xen
- Fedora 40 update for xen
- SUSE update for xen
- SUSE update for xen
- SUSE update for xen
- Speculative race condition in BIG-IP Next Central Manager
- Amazon Linux AMI update for kernel
- Race condition in F5 BIG-IP Linux kernel
- Speculative race condition in F5 F5OS Linux kernel
- Speculative race condition in Traffix SDC Linux kernel
- Gentoo update for Xen
- Debian update for xen
- Multiple vulnerabilities in Dell Cloud Tiering Appliance