Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 21 of 23
CVE-2016-3159P4MEDIUMCVSS 4.3fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-3159 [MEDIUM] CVE-2016-3159: xen - The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle ...
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-20
debian
CVE-2015-7311P4LOWCVSS 3.6fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-7311 [LOW] CVE-2015-7311: xen - libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on d...
libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: reso
debian
CVE-2013-3495P4LOWCVSS 4.7fixed in xen 4.4.1-3 (bookworm)2013
CVE-2013-3495 [MEDIUM] CVE-2013-3495: xen - The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows loca...
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
Scope: local
bookworm: resolved (fixed in 4.4.1-3)
bullseye: resol
debian
CVE-2013-2078P4MEDIUMCVSS 4.7fixed in xen 4.2.2-1 (bookworm)2013
CVE-2013-2078 [MEDIUM] CVE-2013-2078: xen - Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a...
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
Scope: local
bookworm: resolved (fixed in 4.2.2-1)
bullseye: resolved (fixed in 4.2.2-1)
forky: resolved (fixed in 4.2.2-1)
sid: resolved (fixed in 4.2.2-1)
trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2017-7995P4LOWCVSS 3.8fixed in xen 4.3.0-1 (bookworm)2017
CVE-2017-7995 [LOW] CVE-2017-7995: xen - Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after...
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
Scope: local
bookworm: resolved (fixed in 4.3.0-1)
bullseye: resolved (fixed in 4
debian
CVE-2022-42336P4LOWCVSS 3.3fixed in xen 4.17.1+2-gb773c48e36-1 (bookworm)2022
CVE-2022-42336 [LOW] CVE-2022-42336: xen - Mishandling of guest SSBD selection on AMD hardware The current logic to set SSB...
Mishandling of guest SSBD selection on AMD hardware The current logic to set SSBD on AMD Family 17h and Hygon Family 18h processors requires that the setting of SSBD is coordinated at a core level, as the setting is shared between threads. Logic was introduced to keep track of how many threads require SSBD active in order to coordinate it, such logic relies on using a pe
debian
CVE-2023-34321P4LOWCVSS 3.3fixed in xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)2023
CVE-2023-34321 [LOW] CVE-2023-34321: xen - Arm provides multiple helpers to clean & invalidate the cache for a given region...
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalida
debian
CVE-2023-46837P4LOWCVSS 3.3fixed in xen 4.17.3+10-g091466ba55-1~deb12u1 (bookworm)2023
CVE-2023-46837 [LOW] CVE-2023-46837: xen - Arm provides multiple helpers to clean & invalidate the cache for a given region...
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalida
debian
CVE-2015-3340P4LOWCVSS 2.9fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-3340 [LOW] CVE-2015-3340: xen - Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain...
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.
debian
CVE-2013-1918P4MEDIUMCVSS 4.7fixed in xen 4.1.4-4 (bookworm)2013
CVE-2013-1918 [MEDIUM] CVE-2013-1918: xen - Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are ...
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
Scope: local
bookworm: resolved (fixed in 4.1.4-4)
bullseye: resolved (fixed in 4.1.4-4)
forky: resolved (fixed in 4.1.4-4)
sid: resolved (fixed in 4.1.4-4)
trixie:
debian
CVE-2014-8595P4LOWCVSS 1.9fixed in xen 4.4.1-4 (bookworm)2014
CVE-2014-8595 [LOW] CVE-2014-8595: xen - arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly ...
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
Scope: local
bookworm: resolved (fixed in 4.4.1-4)
bullseye: resolved (fixed in 4.4.1-
debian
CVE-2026-23553P4LOWCVSS 2.9fixed in xen 4.20.2+37-g61ff35323e-1 (forky)2026
CVE-2026-23553 [LOW] CVE-2026-23553: xen - In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU r...
In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between vCPUs, this prevents the guest kernel correctly isolating between tasks. Consider: 1) vCPU runs on CPU A, running task 1. 2) vCPU moves to CPU B, idle gets scheduled on A. Xen skips IBPB. 3) On
debian
CVE-2012-2934P4HIGHCVSS 7.2fixed in xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm)2012
CVE-2012-2934 [HIGH] CVE-2012-2934: xen - Xen 4.0, and 4.1, when running a 64-bit PV guest on "older" AMD CPUs, does not p...
Xen 4.0, and 4.1, when running a 64-bit PV guest on "older" AMD CPUs, does not properly protect against a certain AMD processor bug, which allows local guest OS users to cause a denial of service (host hang) via sequential execution of instructions across a non-canonical boundary, a different vulnerability than CVE-2012-0217.
Scope: local
bookworm: resolved (fixed in 4.1.
debian
CVE-2013-4355P4LOWCVSS 1.5fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-4355 [LOW] CVE-2013-4355: xen - Xen 4.3.x and earlier does not properly handle certain errors, which allows loca...
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4
debian
CVE-2014-7156P4LOWCVSS 3.3fixed in xen 4.4.1-3 (bookworm)2014
CVE-2014-7156 [LOW] CVE-2014-7156: xen - The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x thro...
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-3)
bullseye: resolved (fixed in 4.4
debian
CVE-2016-9932P4LOWCVSS 3.3fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-9932 [LOW] CVE-2016-9932: xen - CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM g...
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixi
debian
CVE-2012-2625P4LOWCVSS 2.7fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-2625 [LOW] CVE-2012-2625: xen - The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2....
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
sid: re
debian
CVE-2012-4536P4LOWCVSS 2.1fixed in xen 4.1.3-4 (bookworm)2012
CVE-2012-4536 [LOW] CVE-2012-4536: xen - The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 al...
The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
sid: resolved (fixed in 4.1.3-4)
debian
CVE-2015-6654P4LOWCVSS 2.1fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-6654 [LOW] CVE-2015-6654: xen - The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and...
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.
Scope: local
bookworm: resolved (fixed in 4.
debian
CVE-2012-3432P4LOWCVSS 1.9fixed in xen 4.1.3-1 (bookworm)2012
CVE-2012-3432 [LOW] CVE-2012-3432: xen - The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator fo...
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.
Scope: local
bookworm: resolved (fixed in 4.1.3-1
debian