CVE-2024-31145

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 25, 2024
Updated: Nov 21, 2024
CWE ID 400

Summary

CVE-2024-31145 is a vulnerability affecting certain PCI devices in a system. These devices may be erroneously assigned Reserved Memory Regions (RMRR) for Intel VT-d or Unity Mapping ranges for AMD-Vi, which are typically used for platform tasks. Since the purpose of these regions is unknown once a device is active, the mappings for these regions must remain continuously accessible. However, the error handling logic in establishing these mappings is flawed, potentially allowing respective guests to access memory regions they should not have access to.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share