cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 10 of 23
CVE-2016-1571P4MEDIUMCVSS 6.3fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-1571 [MEDIUM] CVE-2016-1571: xen - The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.... The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check. Scope: local bookworm: resolved (fixed in 4.8.0~rc3
debian
CVE-2023-46839P4MEDIUMCVSS 5.3fixed in xen 4.17.3+10-g091466ba55-1~deb12u1 (bookworm)2023
CVE-2023-46839 [MEDIUM] CVE-2023-46839: xen - PCI devices can make use of a functionality called phantom functions, that when ... PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests. Such phantom functions need an IOMMU context setup, but failure to setup the context is not fatal when the device is
debian
CVE-2015-2751P4HIGHCVSS 7.1fixed in xen 4.4.1-9 (bookworm)2015
CVE-2015-2751 [HIGH] CVE-2015-2751: xen - Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote ... Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations. Scope: local bookworm: resolved (fixed in 4.4.1-9) bullseye: resolved (fixed in 4.4.1-9) forky: resolved (fixed in 4.4.1-9) sid: resolved (fixed in 4.4.1-9) trixie: resolved (fix
debian
CVE-2013-1432P4HIGHCVSS 7.4fixed in xen 4.3.0-1 (bookworm)2013
CVE-2013-1432 [HIGH] CVE-2013-1432: xen - Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly mainta... Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.3.0-1) bullseye: resolved (fixed in 4
debian
CVE-2012-6035P4LOWCVSS 6.9fixed in xen 4.1.4-1 (bookworm)2012
CVE-2012-6035 [MEDIUM] CVE-2012-6035: xen - The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, ... The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly validate pool ids, which allows local guest OS users to cause a denial of service (memory corruption and host crash) or execute arbitrary code via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CV
debian
CVE-2022-26363P4MEDIUMCVSS 6.7fixed in xen 4.16.2-1 (bookworm)2022
CVE-2022-26363 [MEDIUM] CVE-2022-26363: xen - x86 pv: Insufficient care with non-coherent mappings T[his CNA information recor... x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have
debian
CVE-2022-26362P4MEDIUMCVSS 6.4fixed in xen 4.16.2-1 (bookworm)2022
CVE-2022-26362 [MEDIUM] CVE-2022-26362: xen - x86 pv: Race condition in typeref acquisition Xen maintains a type reference cou... x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type reference has a race
debian
CVE-2013-2211P4HIGHCVSS 7.4fixed in xen 4.3.0-1 (bookworm)2013
CVE-2013-2211 [HIGH] CVE-2013-2211: xen - The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses we... The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.3.0-1) bullseye: resolved (fixed in 4.3.0-1) forky: resolved (fixe
debian
CVE-2011-1583P4MEDIUMCVSS 6.9fixed in xen 4.1.1-1 (bookworm)2011
CVE-2011-1583 [MEDIUM] CVE-2011-1583: xen - Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3... Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields. S
debian
CVE-2016-7154P4MEDIUMCVSS 6.7fixed in xen 4.6.0-1 (bookworm)2016
CVE-2016-7154 [MEDIUM] CVE-2016-7154: xen - Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows ... Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number. Scope: local bookworm: resolved (fixed in 4.6.0-1) bullseye: resolved (fixed in 4.6.0-1) forky: resolved (fixed in 4.
debian
CVE-2016-4962P4MEDIUMCVSS 6.7fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-4962 [MEDIUM] CVE-2016-4962: xen - The libxl device-handling in Xen 4.6.x and earlier allows local OS guest adminis... The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore. Scope: local bookworm: resolved (fixed in 4.8.0~rc3-1) bullseye: resolved (fixed in 4.8.0~rc3-1) forky: r
debian
CVE-2023-28746P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-28746 [MEDIUM] CVE-2023-28746: intel-microcode - Information exposure through microarchitectural state after transient execution ... Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 3.20240312.1~deb12u1) bullseye: resolved (fixed in 3.20240312.1~deb11u1) forky:
debian
CVE-2020-15566P4MEDIUMCVSS 6.5fixed in xen 4.11.4+24-gddaaccbbab-1 (bookworm)2020
CVE-2020-15566 [MEDIUM] CVE-2020-15566: xen - An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause ... An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1) port is already in use, (2) the memory allocation failed, or (3) the port we try to allocate is higher than what is supported by
debian
CVE-2017-12855P4MEDIUMCVSS 6.5fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-12855 [MEDIUM] CVE-2017-12855: xen - Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest t... Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant
debian
CVE-2020-29483P4MEDIUMCVSS 6.5fixed in xen 4.14.0+88-g1d1d1f5391-1 (bookworm)2020
CVE-2020-29483 [MEDIUM] CVE-2020-29483: xen - An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate ... An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest violates this protocol, xenstored will drop the connection to that guest. Unfortunately, this is done by just removing the guest from xenstored's internal management, resulting in the same actions as if the guest had been des
debian
CVE-2023-46841P4MEDIUMCVSS 6.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2023
CVE-2023-46841 [MEDIUM] CVE-2023-46841: xen - Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (C... Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming attacks. When enabled, traditional stacks holding both data and return addresses are accompanied by so called "shadow stacks", holding little more tha
debian
CVE-2018-12130P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12130 [MEDIUM] CVE-2018-12130: intel-microcode - Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some micro... Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-in
debian
CVE-2024-36350P4MEDIUMCVSS 5.6fixed in amd64-microcode 3.20251202.1 (forky)2024
CVE-2024-36350 [MEDIUM] CVE-2024-36350: amd64-microcode - A transient execution vulnerability in some AMD processors may allow an attacker... A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.20251202.1) sid: resolved (fixed in 3.20251202.1) trixie: open
debian
CVE-2018-10472P4MEDIUMCVSS 5.6fixed in xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm)2018
CVE-2018-10472 [MEDIUM] CVE-2018-10472: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (i... An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot. Scope: local bookworm: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6) bullseye: resolved (fixed in 4.8.3+
debian
CVE-2023-46835P4MEDIUMCVSS 5.5fixed in xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)2023
CVE-2023-46835 [MEDIUM] CVE-2023-46835: xen - The current setup of the quarantine page tables assumes that the quarantine doma... The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and hence 4 page table levels. However dom_io being a PV domain gets the AMD-Vi IOMMU page tables levels based on the maximum (hot pluggable) RAM address, and hence on systems with no RAM above the
debian
Debian Xen vulnerabilities | cvebase