cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 20 of 23
CVE-2012-3496P4MEDIUMCVSS 4.7fixed in xen 4.1.3-2 (bookworm)2012
CVE-2012-3496 [MEDIUM] CVE-2012-3496: xen - XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and... XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand. Scope: local bookworm: resolved (fixed in 4.1.3-2) bullseye: resolved (fixed in 4.1.3-2) forky:
debian
CVE-2013-0153P4MEDIUMCVSS 4.7fixed in xen 4.1.4-2 (bookworm)2013
CVE-2013-0153 [MEDIUM] CVE-2013-0153: xen - The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using A... The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests. Scope: local bookworm: resolved (fixed in 4.1.4-2) bullseye: resolved (fixed in 4.1.4-2) forky: resolv
debian
CVE-2012-6333P4MEDIUMCVSS 4.7fixed in xen 4.1.3-8 (bookworm)2012
CVE-2012-6333 [MEDIUM] CVE-2012-6333: xen - Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS ... Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input. Scope: local bookworm: resolved (fixed in 4.1.3-8) bullseye: resolved (fixed in 4.1.3-8) forky: resolved (fixed in 4.1.3-8) sid: resolved (fixed in 4.1.3-8) trixie: resolved (fixed in 4.1.3-8)
debian
CVE-2016-4963P4MEDIUMCVSS 4.7fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-4963 [MEDIUM] CVE-2016-4963: xen - The libxl device-handling in Xen through 4.6.x allows local guest OS users with ... The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore. Scope: local bookworm: resolved (fixed in 4.8.0~rc3-1) bullseye: resolved (fixed in 4.8.0~rc3-1) forky: resolved (fixed in 4.8.0~rc3-1) sid
debian
CVE-2012-6031P4LOWCVSS 6.9fixed in xen 4.1.4-1 (bookworm)2012
CVE-2012-6031 [MEDIUM] CVE-2012-6031: xen - The do_tmem_get function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and ... The do_tmem_get function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (CPU hang and host crash) via unspecified vectors related to a spinlock being held in the "bad_copy error path." NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT
debian
CVE-2014-9065P4MEDIUMCVSS 4.4fixed in xen 4.4.1-6 (bookworm)2014
CVE-2014-9065 [MEDIUM] CVE-2014-9065: xen - common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and wri... common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066. Scope: local bookworm: resolved (fixed in 4.4.1-6) bullseye: resolved (fixed in 4.4
debian
CVE-2015-4105P4MEDIUMCVSS 4.9fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4105 [MEDIUM] CVE-2015-4105: qemu - Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error message... Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of service (host disk consumption) via certain invalid operations. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolved (fixed in 1:2.3+dfsg-5) forky: resolved (fixed in 1:2.3+dfsg-5) sid: resolved (fixed in 1:2.3+
debian
CVE-2015-4163P4MEDIUMCVSS 4.9fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-4163 [MEDIUM] CVE-2015-4163: xen - GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table op... GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version. Scope: local bookworm: resolved (fixed in 4.6.0-1) bullseye: resolved (fixed in 4.6.0-1) forky: resolved (fixed in
debian
CVE-2015-7812P4MEDIUMCVSS 4.9fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7812 [MEDIUM] CVE-2015-7812: xen - The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x thr... The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface. Scope: local bookworm: resolved (fixed in 4.6.0-1) bullseye: resolved (fixed in 4.6.0-1) forky: resolved (fixed in 4.6.0-1) sid: resolved (fixed in 4.6.0-1) t
debian
CVE-2013-1922P4LOWCVSS 4.9fixed in qemu 1.5.0+dfsg-1 (bookworm)2013
CVE-2013-1922 [MEDIUM] CVE-2013-1922: qemu - qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk imag... qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004. Scope: local bookworm: resolved (fixed in 1.
debian
CVE-2012-5515P4MEDIUMCVSS 4.7fixed in xen 4.1.3-5 (bookworm)2012
CVE-2012-5515 [MEDIUM] CVE-2012-5515: xen - The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM... The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value. Scope: local bookworm: resolved (fixed in 4.1.3-5) bullseye: resolved (fixed in 4.1.3-5) forky: resolved (fixed in 4.1.3-5) sid: re
debian
CVE-2012-5514P4MEDIUMCVSS 4.7fixed in xen 4.1.3-6 (bookworm)2012
CVE-2012-5514 [MEDIUM] CVE-2012-5514: xen - The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does n... The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.1.3-6) bullseye: resolved (fixed in 4.1.3-6) forky: resolved (fixed in 4.
debian
CVE-2014-5147P4MEDIUMCVSS 4.3fixed in xen 4.4.1-1 (bookworm)2014
CVE-2014-5147 [MEDIUM] CVE-2014-5147: xen - Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly hand... Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process. Scope: local bookworm: resolved (fixed in 4.4.1-1) bullseye: resolved (fixed in 4.4.1-1) forky: resolved (fixed in 4.4.1-1
debian
CVE-2012-4411P4MEDIUMCVSS 4.3fixed in xen 4.1.3-2 (bookworm)2012
CVE-2012-4411 [MEDIUM] CVE-2012-4411: xen - The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrato... The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrators to obtain sensitive host resource information via the qemu monitor. NOTE: this might be a duplicate of CVE-2007-0998. Scope: local bookworm: resolved (fixed in 4.1.3-2) bullseye: resolved (fixed in 4.1.3-2) forky: resolved (fixed in 4.1.3-2) sid: resolved (fixed in 4.1.3-2) trixie: resolv
debian
CVE-2016-7094P4MEDIUMCVSS 4.1fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-7094 [MEDIUM] CVE-2016-7094: xen - Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administr... Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update. Scope: local bookworm: resolved (fixed in 4.8.0~rc3-1) bullseye: resolved (fixed in 4.8.0~rc3-1) forky: resolved (fixed in 4.8.0~rc3-1) sid: resolved (fixed in 4.8.0~rc3-1) trixie: resolved (fixed
debian
CVE-2022-33747P4LOWCVSS 3.8fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-33747 [LOW] CVE-2022-33747: xen - Arm: unbounded memory consumption for 2nd-level page tables Certain actions requ... Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are
debian
CVE-2014-8866P4MEDIUMCVSS 4.7fixed in xen 4.4.1-5 (bookworm)2014
CVE-2014-8866 [MEDIUM] CVE-2014-8866: xen - The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x... The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode. Scope: local bookworm: resolved (fixed in 4.4.1-5) bullseye: resolved (fixed in 4.4.1-5) forky: re
debian
CVE-2012-5510P4MEDIUMCVSS 4.7fixed in xen 4.1.3-5 (bookworm)2012
CVE-2012-5510 [MEDIUM] CVE-2012-5510: xen - Xen 4.x, when downgrading the grant table version, does not properly remove the ... Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.1.3-5) bullseye: resolved (fixed in 4.1.3-5) forky: resolved (fixed in 4.1
debian
CVE-2013-2076P4LOWCVSS 2.1fixed in xen 4.2.2-1 (bookworm)2013
CVE-2013-2076 [LOW] CVE-2013-2076: xen - Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore... Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerabi
debian
CVE-2016-3158P4MEDIUMCVSS 4.3fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-3158 [MEDIUM] CVE-2016-3158: xen - The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle wri... The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
debian
Debian Xen vulnerabilities | cvebase