cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 13 of 23
CVE-2022-42313P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42313 [MEDIUM] CVE-2022-42313: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2022-42311P4MEDIUMCVSS 6.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42311 [MEDIUM] CVE-2022-42311: xen - Xenstore: guests can let run xenstored out of memory T[his CNA information recor... Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large
debian
CVE-2024-28956P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2024
CVE-2024-28956 [MEDIUM] CVE-2024-28956: intel-microcode - Exposure of Sensitive Information in Shared Microarchitectural Structures during... Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. Scope: local bookworm: resolved (fixed in 3.20250512.1~deb12u1) bullseye: resolved (fixed in 3.20250512.1~deb11u1) forky: resolved (f
debian
CVE-2019-11091P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2019
CVE-2019-11091 [MEDIUM] CVE-2019-11091: intel-microcode - Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory ... Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents
debian
CVE-2018-10471P4MEDIUMCVSS 5.6fixed in xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm)2018
CVE-2018-10471 [MEDIUM] CVE-2018-10471: xen - An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to ... An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754. Scope: local bookworm: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6) bullseye: resolved (fixed in 4.8.3+xsa262+shim4.10.0
debian
CVE-2020-11740P4MEDIUMCVSS 5.5fixed in xen 4.11.4-1 (bookworm)2020
CVE-2020-11740 [MEDIUM] CVE-2020-11740: xen - An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS use... An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed. Scope: local bookworm: resolved (fixed in 4.11.4-1) bullseye:
debian
CVE-2021-26933P4MEDIUMCVSS 5.5fixed in xen 4.14.1+11-gb0b734a8b3-1 (bookworm)2021
CVE-2021-26933 [MEDIUM] CVE-2021-26933: xen - An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to... An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory before handing over the page to a guest. Unfortunately, the operation to clean the cache is happening before checking if
debian
CVE-2024-45819P4MEDIUMCVSS 5.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-45819 [MEDIUM] CVE-2024-45819: xen - PVH guests have their ACPI tables constructed by the toolstack. The constructio... PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents. Scope: local bookworm: resolved (fixed in 4.17.5+23-ga4e5191d
debian
CVE-2022-42323P4MEDIUMCVSS 5.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42323 [MEDIUM] CVE-2022-42323: xen - Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA inf... Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be modified to be owned by Dom0. This will allow two malicious guests working together to create an
debian
CVE-2022-42322P4MEDIUMCVSS 5.5fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42322 [MEDIUM] CVE-2022-42322: xen - Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA inf... Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be modified to be owned by Dom0. This will allow two malicious guests working together to create an
debian
CVE-2022-42331P4MEDIUMCVSS 5.5fixed in xen 4.17.0+74-g3eac216e6e-1 (bookworm)2022
CVE-2022-42331 [MEDIUM] CVE-2022-42331: xen - x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the ... x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative attacks. Scope: local bookworm: resolved (fixed in 4.1
debian
CVE-2013-6400P4MEDIUMCVSS 6.8fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-6400 [MEDIUM] CVE-2013-6400: xen - Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, d... Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspecified errors occur, which causes the TLB entries to not be flushed and allows local guest administrators to cause a denial of service (host crash) or gain privileges via unspecified vectors. Scope: local bookworm: resolved (
debian
CVE-2018-12207P4MEDIUMCVSS 6.5fixed in linux 5.3.9-2 (bookworm)2018
CVE-2018-12207 [MEDIUM] CVE-2018-12207: linux - Improper invalidation for page table updates by a virtual guest operating system... Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. Scope: local bookworm: resolved (fixed in 5.3.9-2) bullseye: resolved (fixed in 5.3.9-2) forky: resolved (fixed in 5.3.9-2) sid: resolved (fixed
debian
CVE-2018-19967P4MEDIUMCVSS 6.5fixed in xen 4.11.1-1 (bookworm)2018
CVE-2018-19967 [MEDIUM] CVE-2018-19967: xen - An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing gu... An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix. Scope: local bookworm: resolved (fixed in 4.11.1-1) bullseye: resolved (fixed in 4.11.1-1) forky: resol
debian
CVE-2018-10981P4MEDIUMCVSS 6.5fixed in xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm)2018
CVE-2018-10981 [MEDIUM] CVE-2018-10981: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to... An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request. Scope: local bookworm: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6) bullseye: resolved (fixed in 4.8.3+xsa262+shim4.10
debian
CVE-2017-17044P4MEDIUMCVSS 6.5fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-17044 [MEDIUM] CVE-2017-17044: xen - An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to caus... An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors. Scope: local bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1) bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1) forky: resolved (fixed in 4.8.2+xsa245-0+deb9u1) sid
debian
CVE-2018-7540P4MEDIUMCVSS 6.5fixed in xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm)2018
CVE-2018-7540 [MEDIUM] CVE-2018-7540: xen - An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to ... An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing. Scope: local bookworm: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5) bullseye: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5) forky: resolved (fixed in 4.8.3+comet2+shim4.10.0
debian
CVE-2017-14318P4MEDIUMCVSS 6.5fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-14318 [MEDIUM] CVE-2017-14318: xen - An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache... An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush grant table operations. It checks to see if the calling domain is the owner of the page that is to be operated on. If it is not, the owner's grant table is checked to see if a grant mapping to the calling domain exists for the page in question. However,
debian
CVE-2019-17344P4MEDIUMCVSS 6.5fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17344 [MEDIUM] CVE-2019-17344: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ... An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates. Scope: local bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1) bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1) forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
debian
CVE-2019-17345P4MEDIUMCVSS 6.5fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17345 [MEDIUM] CVE-2019-17345: xen - An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS use... An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest. Scope: local bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1) bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1) forky: resolved (fixed in 4.11.1
debian
Debian Xen vulnerabilities | cvebase