Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 19 of 23
CVE-2015-7814P4MEDIUMCVSS 4.7fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7814 [MEDIUM] CVE-2015-7814: xen - Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6...
Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6.x and earlier allows local domains with partial management control to cause a denial of service (host crash) via vectors involving the destruction of a domain and using XENMEM_decrease_reservation to reduce the memory of the domain.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullsey
debian
CVE-2015-4106P4MEDIUMCVSS 4.6fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4106 [MEDIUM] CVE-2015-4106: qemu - QEMU does not properly restrict write access to the PCI config space for certain...
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-5)
bullseye: resolv
debian
CVE-2014-1950P4MEDIUMCVSS 4.6fixed in xen 4.4.0-1 (bookworm)2014
CVE-2014-1950 [MEDIUM] CVE-2014-1950: xen - Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x thr...
Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors.
Scope: local
debian
CVE-2022-23035P4MEDIUMCVSS 4.6fixed in xen 4.16.0+51-g0941d6cb-1 (bookworm)2022
CVE-2022-23035 [MEDIUM] CVE-2022-23035: xen - Insufficient cleanup of passed-through device IRQs The management of IRQs associ...
Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be scheduled to be ret
debian
CVE-2023-46840P4MEDIUMCVSS 4.1fixed in xen 4.17.3+10-g091466ba55-1~deb12u1 (bookworm)2023
CVE-2023-46840 [MEDIUM] CVE-2023-46840: xen - Incorrect placement of a preprocessor directive in source code results in logic ...
Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out of Xen.
Scope: local
bookworm: resolved (fixed in 4.17.3+10-g091466ba55-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 4.17.3+10-g091466ba55-1)
sid: resolved (fixed in 4.17.3+10-g091466ba55-1)
trixie: res
debian
CVE-2014-3968P4MEDIUMCVSS 5.5fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-3968 [MEDIUM] CVE-2014-3968: xen - The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest ...
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed
debian
CVE-2014-3967P4MEDIUMCVSS 5.5fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-3967 [MEDIUM] CVE-2014-3967: xen - The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly c...
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolved (fix
debian
CVE-2011-1166P4MEDIUMCVSS 5.5fixed in xen 4.1.0-1 (bookworm)2011
CVE-2011-1166 [MEDIUM] CVE-2011-1166: xen - Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of s...
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
Scope: local
bookworm: resolved (fixed in 4.1.0-1)
bullseye: resolved (fixed in 4.1.0-1)
forky: resolved (fixed in 4.1.0-1)
sid: resolved (fixed in 4.1.0-1)
trixie: resolved (fixed in 4.1.0-1)
debian
CVE-2012-4538P4MEDIUMCVSS 4.9fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-4538 [MEDIUM] CVE-2012-4538: xen - The HVMOP_pagetable_dying hypercall in Xen 4.0, 4.1, and 4.2 does not properly c...
The HVMOP_pagetable_dying hypercall in Xen 4.0, 4.1, and 4.2 does not properly check the pagetable state when running on shadow pagetables, which allows a local HVM guest OS to cause a denial of service (hypervisor crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
s
debian
CVE-2015-8340P4MEDIUMCVSS 4.7fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-8340 [MEDIUM] CVE-2015-8340: xen - The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does ...
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might allow guest OS administrators to cause a denial of service (deadlock or host crash) via unspecified vectors, related to XENMEM_exchange error handling.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
for
debian
CVE-2020-25604P4MEDIUMCVSS 4.7fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-25604 [MEDIUM] CVE-2020-25604: xen - An issue was discovered in Xen through 4.14.x. There is a race condition when mi...
An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The most likely effect of the issue is a hang or crash
debian
CVE-2011-3131P4MEDIUMCVSS 4.6fixed in xen 4.1.2-1 (bookworm)2011
CVE-2011-3131 [MEDIUM] CVE-2011-3131: xen - Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] dev...
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
Scope: local
bookworm: resolved (fixed in 4.1.2-1)
bullseye: resolved (fixed in 4.1.2-1)
forky: resolved (fixed in 4.1.2-1)
sid: resolved (f
debian
CVE-2014-5148P4MEDIUMCVSS 4.6fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-5148 [MEDIUM] CVE-2014-5148: xen - Xen 4.4.x, when running on an ARM system and "handling an unknown system registe...
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted
debian
CVE-2015-4164P4MEDIUMCVSS 4.9fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-4164 [MEDIUM] CVE-2015-4164: xen - The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a...
The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of service (large loop and system hang) via a hypercall_iret call with EFLAGS.VM set.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: re
debian
CVE-2012-3433P4MEDIUMCVSS 4.9fixed in xen 4.1.3-1 (bookworm)2012
CVE-2012-3433 [MEDIUM] CVE-2012-3433: xen - Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (...
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: reso
debian
CVE-2014-6268P4MEDIUMCVSS 4.9fixed in xen 4.4.1-3 (bookworm)2014
CVE-2014-6268 [MEDIUM] CVE-2014-6268: xen - The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to ca...
The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via vectors involving an uninitialized FIFO-based event channel control block when (1) binding or (2) moving an event to a different VCPU.
Scope: local
bookworm: resolved (fixed in 4.4.1-3)
bullseye: resolved (fixed in 4.4.1-3)
forky: resolved (fixed in 4
debian
CVE-2014-2599P4MEDIUMCVSS 4.9fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-2599 [MEDIUM] CVE-2014-2599: xen - The HVMOP_set_mem_access HVM control operations in Xen 4.1.x for 32-bit and 4.1....
The HVMOP_set_mem_access HVM control operations in Xen 4.1.x for 32-bit and 4.1.x through 4.4.x for 64-bit allow local guest administrators to cause a denial of service (CPU consumption) by leveraging access to certain service domains for HVM guests and a large input.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolve
debian
CVE-2010-2938P4MEDIUMCVSS 4.9fixed in xen 4.0.1-1 (bookworm)2010
CVE-2010-2938 [MEDIUM] CVE-2010-2938: xen - arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implemen...
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS cr
debian
CVE-2014-5146P4LOWCVSS 4.7fixed in xen 4.4.1-4 (bookworm)2014
CVE-2014-5146 [MEDIUM] CVE-2014-5146: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa9...
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
Scope: local
boo
debian
CVE-2014-5149P4LOWCVSS 4.7fixed in xen 4.4.1-4 (bookworm)2014
CVE-2014-5149 [MEDIUM] CVE-2014-5149: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using sha...
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
Scope: local
bookworm: resolved (fixed in 4.4.1-4)
bulls
debian