device to use multiple consecutive interrupt vectors. Unlike for MSI-X,
the setting up of these consecutive vectors needs to happen all in one
go. In this handling an error path could be taken in different
situations, with or without a particular lock held. This error path
wrongly releases the lock even when it is not currently held.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Not passing through multi-vector MSI capable devices to x86 guests will avoid the vulnerability.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5836-1 | xen security update |
EUVD |
EUVD-2024-29053 | An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling an error path could be taken in different situations, with or without a particular lock held. This error path wrongly releases the lock even when it is not currently held. |
Wed, 14 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* |
Sat, 26 Apr 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 26 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xen
Xen xen |
|
| CPEs | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xen
Xen xen |
|
| Metrics |
ssvc
|
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 21 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-832 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2025-04-26T20:03:16.232Z
Reserved: 2024-03-28T18:14:12.892Z
Link: CVE-2024-31143
Updated: 2025-04-26T20:03:16.232Z
Status : Analyzed
Published: 2024-07-18T14:15:04.673
Modified: 2026-01-14T16:31:30.927
Link: CVE-2024-31143
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD