Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 11 of 23
CVE-2020-27674P4MEDIUMCVSS 5.3fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-27674 [MEDIUM] CVE-2020-27674: xen - An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Scope: local
bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1)
bullseye: resolved (fixed in 4.14.0+80-gd101b417b7-1)
forky: res
debian
CVE-2015-8338P4HIGHCVSS 7.2fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-8338 [HIGH] CVE-2015-8338: xen - Xen 4.6.x and earlier does not properly enforce limits on page order inputs for ...
Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly
debian
CVE-2015-3259P4LOWCVSS 6.8fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-3259 [MEDIUM] CVE-2015-3259: xen - Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through ...
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
debian
CVE-2021-28694P4MEDIUMCVSS 6.8fixed in xen 4.14.3-1 (bookworm)2021
CVE-2021-28694 [MEDIUM] CVE-2021-28694: xen - IOMMU page mapping issues on x86 T[his CNA information record relates to multipl...
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typicall
debian
CVE-2021-28695P4MEDIUMCVSS 6.8fixed in xen 4.14.3-1 (bookworm)2021
CVE-2021-28695 [MEDIUM] CVE-2021-28695: xen - IOMMU page mapping issues on x86 T[his CNA information record relates to multipl...
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typicall
debian
CVE-2021-28696P4MEDIUMCVSS 6.8fixed in xen 4.14.3-1 (bookworm)2021
CVE-2021-28696 [MEDIUM] CVE-2021-28696: xen - IOMMU page mapping issues on x86 T[his CNA information record relates to multipl...
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typicall
debian
CVE-2022-23825P4MEDIUMCVSS 6.5fixed in xen 4.16.2-1 (bookworm)2022
CVE-2022-23825 [MEDIUM] CVE-2022-23825: xen - Aliases in the branch predictor may cause some AMD processors to predict the wro...
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
Scope: local
bookworm: resolved (fixed in 4.16.2-1)
bullseye: resolved (fixed in 4.14.5+24-g87d90d511c-1)
forky: resolved (fixed in 4.16.2-1)
sid: resolved (fixed in 4.16.2-1)
trixie: resolved (fixed in 4.16.2-1)
debian
CVE-2020-15563P4MEDIUMCVSS 6.5fixed in xen 4.11.4+24-gddaaccbbab-1 (bookworm)2020
CVE-2020-15563 [MEDIUM] CVE-2020-15563: xen - An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users t...
An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM guest may cause the hypervisor to crash, resulting in Denial of Service
debian
CVE-2017-17046P4MEDIUMCVSS 6.5fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-17046 [MEDIUM] CVE-2017-17046: xen - An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest ...
An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved
debian
CVE-2022-42321P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42321 [MEDIUM] CVE-2022-42321: xen - Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using...
Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting a sub-tree of Xenstore nodes). With sufficiently deep nesting levels this can result in stack exhaustion on xenstored, leading to a crash of xenstored.
Scope: local
bookworm: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
bullseye: re
debian
CVE-2022-42319P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42319 [MEDIUM] CVE-2022-42319: xen - Xenstore: Guests can cause Xenstore to not free temporary memory When working on...
Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finished completely. A request is regarded to be finished only after the guest has read the response message of the request from the ring
debian
CVE-2022-42334P4HIGHCVSS 8.6fixed in xen 4.17.0+74-g3eac216e6e-1 (bookworm)2022
CVE-2022-42334 [HIGH] CVE-2022-42334: xen - x86/HVM pinned cache attributes mis-handling T[his CNA information record relate...
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not exposed to the affected
debian
CVE-2014-8594P4LOWCVSS 5.4fixed in xen 4.4.1-4 (bookworm)2014
CVE-2014-8594 [MEDIUM] CVE-2014-8594: xen - The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not pr...
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation services for HVM guests using Hardware Assisted Paging (HAP).
Scope: local
bookworm: resolved (fixed in 4.4.1-4)
bullseye: re
debian
CVE-2018-12127P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12127 [MEDIUM] CVE-2018-12127: intel-microcode - Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microproc...
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-inform
debian
CVE-2018-12126P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12126 [MEDIUM] CVE-2018-12126: intel-microcode - Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some mic...
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-
debian
CVE-2024-36357P4MEDIUMCVSS 5.6fixed in amd64-microcode 3.20251202.1 (forky)2024
CVE-2024-36357 [MEDIUM] CVE-2024-36357: amd64-microcode - A transient execution vulnerability in some AMD processors may allow an attacker...
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.20251202.1)
sid: resolved (fixed in 3.20251202.1)
trixie: open
debian
CVE-2021-28700P4MEDIUMCVSS 4.9fixed in xen 4.14.3-1 (bookworm)2021
CVE-2021-28700 [MEDIUM] CVE-2021-28700: xen - xen/arm: No memory limit for dom0less domUs The dom0less feature allows an admin...
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
Scope: local
bookworm: resolved (fixed in 4.14.3-1)
bullseye: resolved (fixed
debian
CVE-2021-26313P4MEDIUMCVSS 5.5fixed in xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)2021
CVE-2021-26313 [MEDIUM] CVE-2021-26313: xen - Potential speculative code store bypass in all supported CPU products, in conjun...
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
Scope: local
bookworm: resolved (fixed in 4.14.2+25-gb6a8c4f72d-1)
bullseye: resolved (fixed in 4.14.2+25-gb6a8c4f72d-1)
f
debian
CVE-2014-3124P4MEDIUMCVSS 6.7fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-3124 [MEDIUM] CVE-2014-3124: xen - The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM a...
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved
debian
CVE-2019-17343P4MEDIUMCVSS 6.8fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17343 [MEDIUM] CVE-2019-17343: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
si
debian