Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 2 of 23
CVE-2017-10921P3CRITICALCVSS 10.0fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10921 [CRITICAL] CVE-2017-10921: xen - The grant-table feature in Xen through 4.8.x does not ensure sufficient type cou...
The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolv
debian
CVE-2019-18423P3HIGHCVSS 8.8fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-18423 [HIGH] CVE-2019-18423: xen - An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cau...
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() and p2m_get_entry() to sanity check guest physical frame. The rest of the code in the two functions will assume that there is a valid root table and chec
debian
CVE-2012-6075P3CRITICALCVSS 9.3fixed in qemu 1.1.2+dfsg-4 (bookworm)2012
CVE-2012-6075 [CRITICAL] CVE-2012-6075: qemu - Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e10...
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Scope: local
bookworm: resolved (fixed in 1.1.2+dfsg-4)
bullseye: resolv
debian
CVE-2019-18422P3HIGHCVSS 8.8fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-18422 [HIGH] CVE-2019-18422: xen - An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cau...
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an exception occurs on an ARM system which is handled without changing processor level, some interrupts are unconditionally enable
debian
CVE-2019-18421P3HIGHCVSS 7.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-18421 [HIGH] CVE-2019-18421: xen - An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for PV guests, Xen exposes the actual hardware pagetables to the guest. In order to prevent the
debian
CVE-2012-5513P4MEDIUMCVSS 6.9PoCfixed in xen 4.1.3-5 (bookworm)2012
CVE-2012-5513 [MEDIUM] CVE-2012-5513: xen - The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the m...
The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.
Scope: local
bookworm: resolved (fixed in 4.1.3-5)
bullseye: resolved (fixed in 4.1.3-
debian
CVE-2025-58150P3HIGHCVSS 8.8fixed in xen 4.20.2+37-g61ff35323e-1 (forky)2025
CVE-2025-58150 [HIGH] CVE-2025-58150: xen - Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome par...
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.20.2+37-g61ff35323e-1)
sid:
debian
CVE-2025-58143P3CRITICALCVSS 9.8fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58143 [CRITICAL] CVE-2025-58143: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by a
debian
CVE-2016-3710P3HIGHCVSS 8.8fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-3710 [HIGH] CVE-2016-3710: qemu - The VGA module in QEMU improperly performs bounds checking on banked access to v...
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: resolv
debian
CVE-2017-10913P3CRITICALCVSS 9.8fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10913 [CRITICAL] CVE-2017-10913: xen - The grant-table feature in Xen through 4.8.x provides false mapping information ...
The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u
debian
CVE-2025-58148P3HIGHCVSS 7.5fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58148 [HIGH] CVE-2025-58148: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147.
debian
CVE-2025-58147P3HIGHCVSS 7.5fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58147 [HIGH] CVE-2025-58147: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147.
debian
CVE-2025-58142P3CRITICALCVSS 9.8fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58142 [CRITICAL] CVE-2025-58142: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by a
debian
CVE-2025-27466P3CRITICALCVSS 9.8fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-27466 [CRITICAL] CVE-2025-27466: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by a
debian
CVE-2017-8903P3HIGHCVSS 8.8fixed in xen 4.8.1-1+deb9u1 (bookworm)2017
CVE-2017-8903 [HIGH] CVE-2017-8903: xen - Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hyper...
Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-213.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u1)
bullseye: resolved (fixed in 4.8.1-1+deb9u1)
forky: resolved (fixed in 4.8.1-1+deb9u1)
sid: resolved (fixed in 4.8.1-1+deb9u1)
trixie: reso
debian
CVE-2017-8905P3HIGHCVSS 8.8fixed in xen 4.8.0~rc3-1 (bookworm)2017
CVE-2017-8905 [HIGH] CVE-2017-8905: xen - Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which migh...
Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
debian
CVE-2019-19578P3HIGHCVSS 8.8fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19578 [HIGH] CVE-2019-19578: xen - An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at itself, or to another pagetable of the same or higher level. Xen has limited support for line
debian
CVE-2020-15565P3HIGHCVSS 8.8fixed in xen 4.11.4+24-gddaaccbbab-1 (bookworm)2020
CVE-2020-15565 [HIGH] CVE-2020-15565: xen - An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS u...
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require flushing of both TLBs. Furthermore, IOMMUs may be non-coherent, and hence prior to flushing IO
debian
CVE-2020-29479P3HIGHCVSS 8.8fixed in xen 4.14.0+88-g1d1d1f5391-1 (bookworm)2020
CVE-2020-29479 [HIGH] CVE-2020-29479: xen - An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementa...
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unfortunately, permissions were not checked for certain operations on the root node. Unprivileged guests can get and modify permissions, list, and delete the root node. (Deleti
debian
CVE-2017-10915P3CRITICALCVSS 9.0fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10915 [CRITICAL] CVE-2017-10915: xen - The shadow-paging feature in Xen through 4.8.x mismanages page references and co...
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9
debian