Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-2193

21
FAUCET Score

CVE-2024-2193 is a Speculative Race Condition (SRC) vulnerability affecting modern CPU architectures that support speculative execution, similar to Spectre V1. This flaw allows an unauthenticated attacker to disclose arbitrary data from the CPU by exploiting race conditions within speculative code paths. Rated as Medium severity with a CVSS score of 5.7, the vulnerability requires high privileges (PR:H) and high attack complexity (AC:H) but can lead to high confidentiality (C:H) and integrity (I:H) impacts. While there is no known active exploitation, exploit code, or KEV listing, the vulnerability has garnered significant community attention with two media articles and two community discussions.

Impacted Technologies

VendorProductVersion(s)CPE
AMDCPU
See advisory AMD-SB-7016CNA affected
XenXen
consult Xen advisory XSA-453CNA affected

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.5
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.23%
Probability of exploitation in next 30 days
EPSS Percentile
65.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0123 is in the 96th percentile among its peer group of 418 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-2193Moderate

hw: Spectre-SRC that is Speculative Race Conditions (SRCs) for synchronization primitives similar like Spectre V1 with possibility to bypass software features (e.g., IPIs, high-precision timers, etc)

Mar 12, 2024

References

xenbits.xen.org / xsa/advisory-453.html
download.vusec.net / papers/ghostrace_sec24.pdf
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/patch
ibm.github.io / system-security-research-updates/2024/03/12/ghostrace
kb.cert.org / vuls/id/488902
lists.fedoraproject.org / archives/list/[email protected]/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK
lists.fedoraproject.org / archives/list/[email protected]/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG
lists.fedoraproject.org / archives/list/[email protected]/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A
amd.com / en/resources/product-security/bulletin/amd-sb-7016.html
kb.cert.org / vuls/id/488902
vusec.net / projects/ghostrace
xenbits.xen.org / xsa/advisory-453.html
openwall.com / lists/oss-security/2024/03/12/14