cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 12 of 23
CVE-2020-15564P4MEDIUMCVSS 6.5fixed in xen 4.11.4+24-gddaaccbbab-1 (bookworm)2020
CVE-2020-15564 [MEDIUM] CVE-2020-15564: xen - An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to ca... An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared region with the hypervisor. The region will be mapped into Xen address space so it can be directly accessed. On Arm, the
debian
CVE-2016-9384P4MEDIUMCVSS 6.5fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-9384 [MEDIUM] CVE-2016-9384: xen - Xen 4.7 allows local guest OS users to obtain sensitive host information by load... Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table. Scope: local bookworm: resolved (fixed in 4.8.0-1) bullseye: resolved (fixed in 4.8.0-1) forky: resolved (fixed in 4.8.0-1) sid: resolved (fixed in 4.8.0-1) trixie: resolved (fixed in 4.8.0-1)
debian
CVE-2021-0089P4MEDIUMCVSS 6.5fixed in xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)2021
CVE-2021-0089 [MEDIUM] CVE-2021-0089: xen - Observable response discrepancy in some Intel(R) Processors may allow an authori... Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 4.14.2+25-gb6a8c4f72d-1) bullseye: resolved (fixed in 4.14.2+25-gb6a8c4f72d-1) forky: resolved (fixed in 4.14.2+25-gb6a8c4f72d-1) sid: resolved (fixed in 4.14.2+25-gb6a8c4f72d-1)
debian
CVE-2020-25597P4MEDIUMCVSS 6.5fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-25597 [MEDIUM] CVE-2020-25597: xen - An issue was discovered in Xen through 4.14.x. There is mishandling of the const... An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not become invalid over the life time of a guest. However, operations like the resetting of all event channels may involve dec
debian
CVE-2018-3665P4MEDIUMCVSS 5.6fixed in linux 4.6.1-1 (bookworm)2018
CVE-2018-3665 [MEDIUM] CVE-2018-3665: linux - System software utilizing Lazy FP state restore technique on systems using Intel... System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. Scope: local bookworm: resolved (fixed in 4.6.1-1) bullseye: resolved (fixed in 4.6.1-1) forky: resolved (fixed in 4.6.1-1) sid: resolved (fixe
debian
CVE-2016-2270P4MEDIUMCVSS 6.8fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-2270 [MEDIUM] CVE-2016-2270: xen - Xen 4.6.x and earlier allows local guest administrators to cause a denial of ser... Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings. Scope: local bookworm: resolved (fixed in 4.8.0~rc3-1) bullseye: resolved (fixed in 4.8.0~rc3-1) forky: resolved (fixed in 4.8.0~rc3-1) sid: resolved (fixed in 4.8.0~rc3-1) trixie:
debian
CVE-2012-6030P4LOWCVSS 6.9fixed in xen 4.1.4-1 (bookworm)2012
CVE-2012-6030 [MEDIUM] CVE-2012-6030: xen - The do_tmem_op function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4... The do_tmem_op function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (host crash) and possibly have other unspecified impacts via unspecified vectors related to "broken locking checks" in an "error path." NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-20
debian
CVE-2013-4329P4MEDIUMCVSS 6.5fixed in xen 4.3.0-1 (bookworm)2013
CVE-2013-4329 [MEDIUM] CVE-2013-4329: xen - The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled,... The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction. Scope: local bookworm: resolved (fixed in 4.3.0-1) bullseye: resolved (fixed in 4.
debian
CVE-2018-12891P4MEDIUMCVSS 6.5fixed in xen 4.8.3+xsa267+shim4.10.1+xsa267-1+deb9u9 (bookworm)2018
CVE-2018-12891 [MEDIUM] CVE-2018-12891: xen - An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may tak... An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for the need to preempt the current vCPU at certain points. A few rarely taken code paths did bypass such checks. By suitably enforcing the conditions through its own page table contents, a malicious guest may cause such bypas
debian
CVE-2018-15469P4MEDIUMCVSS 6.5fixed in xen 4.11.1~pre.20180911.5acdd26fdc+dfsg-2 (bookworm)2018
CVE-2018-15469 [MEDIUM] CVE-2018-15469: xen - An issue was discovered in Xen through 4.11.x. ARM never properly implemented gr... An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in subsequent grant-related hypercalls hitting BUG() checks. An unprivileged guest can cause a BUG() check in the hypervisor
debian
CVE-2018-12893P4MEDIUMCVSS 6.5fixed in xen 4.8.3+xsa267+shim4.10.1+xsa267-1+deb9u9 (bookworm)2018
CVE-2018-12893 [MEDIUM] CVE-2018-12893: xen - An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added... An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug exceptions. Unfortunately, due to an oversight, at least one of these safety checks can be triggered by a guest. A malicious PV guest can crash Xen, leading to a Denial of Service. All Xen systems which have applied the XSA-260
debian
CVE-2018-15470P4LOWCVSS 6.5fixed in xen 4.11.1~pre.20180911.5acdd26fdc+dfsg-2 (bookworm)2018
CVE-2018-15470 [MEDIUM] CVE-2018-15470: xen - An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handl... An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making up a tuple. As indicated in section 7.7.3 "Operations on data structures" of the OCaml manual, the order of evaluation of subexpressions is not specified. In practice, different implementations behave differently. Thus, o
debian
CVE-2019-19582P4MEDIUMCVSS 6.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19582 [MEDIUM] CVE-2019-19582: xen - An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cau... An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On x86 accesses to bitmaps with
debian
CVE-2019-19581P4MEDIUMCVSS 6.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19581 [MEDIUM] CVE-2019-19581: xen - An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users... An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On 32-bit Arm acc
debian
CVE-2022-42317P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42317 [MEDIUM] CVE-2022-42317: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2022-42312P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42312 [MEDIUM] CVE-2022-42312: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2022-42318P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42318 [MEDIUM] CVE-2022-42318: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2022-42316P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42316 [MEDIUM] CVE-2022-42316: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2022-42315P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42315 [MEDIUM] CVE-2022-42315: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2022-42314P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42314 [MEDIUM] CVE-2022-42314: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
Debian Xen vulnerabilities | cvebase