kernel CVE-2024-2193
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.19.3
Patched versions
1.19.3
kernel-5.15
(bottlerocket)
< 1.19.3
1.19.3
kernel-6.1
(bottlerocket)
< 1.19.3
1.19.3
A new cache speculation vulnerability, known as Spectre-SRC (Speculative Race Conditions), was found in hw. Spectre-SRC is similar to the Spectre v1 and allows speculative use-after-free. The difference between this issue and Spectre V1 is that this issue is based on synchronization primitives with the possibility to bypass software features such as IPIs and high-precision timers, which may disclose arbitrary data from a privileged component that should not be accessible.