CVE-2024-2201 is a cross-privilege Spectre v2 vulnerability impacting Linux kernel memory on Intel systems, allowing attackers to bypass existing mitigations like FineIBT. With a CVSS score of 4.7 (Medium), exploitation requires local access and high attack complexity, but can lead to arbitrary kernel memory leakage. While not currently in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage are minimal, suggesting low immediate exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Xen | Xen | See advisory "x86: Native Branch History Injection"CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Spectre branch target injection ("VMScape")
Nov 19, 2025Spectre branch target injection ("VMScape") fix
Nov 19, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025CVE-2024-2201
Dec 10, 2024hw: cpu: intel: Native Branch History Injection (BHI)
Apr 9, 2024