Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 3 of 23
CVE-2021-28706P3HIGHCVSS 8.6fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28706 [HIGH] CVE-2021-28706: xen - guests may exceed their designated memory limit When a guest is permitted to hav...
guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which g
debian
CVE-2022-42333P3HIGHCVSS 8.6fixed in xen 4.17.0+74-g3eac216e6e-1 (bookworm)2022
CVE-2022-42333 [HIGH] CVE-2022-42333: xen - x86/HVM pinned cache attributes mis-handling T[his CNA information record relate...
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not exposed to the affected
debian
CVE-2016-6258P3HIGHCVSS 8.8fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-6258 [HIGH] CVE-2016-6258: xen - The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-...
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie
debian
CVE-2017-15597P3CRITICALCVSS 9.1fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15597 [CRITICAL] CVE-2017-15597: xen - An issue was discovered in Xen through 4.9.x. Grant copying code made an implica...
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator
debian
CVE-2025-58149P3HIGHCVSS 7.5fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58149 [HIGH] CVE-2025-58149: xen - When passing through PCI devices, the detach logic in libxl won't remove access ...
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assigned to the domain. For PV domains the permission leak allows the domain itself to map the memory in the page-tables. For HVM it would
debian
CVE-2017-8904P3HIGHCVSS 8.8fixed in xen 4.8.1-1+deb9u1 (bookworm)2017
CVE-2017-8904 [HIGH] CVE-2017-8904: xen - Xen through 4.8.x mishandles the "contains segment descriptors" property during ...
Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u1)
bullseye: resolved (fixed in 4.8.1-1+deb9u1)
forky: resolved (fixed in 4.8.1-1+deb9u1)
sid: re
debian
CVE-2017-14316P3HIGHCVSS 8.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-14316 [HIGH] CVE-2017-14316: xen - A parameter verification issue was discovered in Xen through 4.9.x. The function...
A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node that should be used for allocations through the `memflags` parameter; the node is extracted using the `MEMF_get_node` macro. While the function checks to see if the special constant `NUMA_NO_NODE` is specified, it otherwise do
debian
CVE-2021-28707P3HIGHCVSS 8.8fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28707 [HIGH] CVE-2021-28707: xen - PoD operations on misaligned GFNs T[his CNA information record relates to multip...
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pa
debian
CVE-2021-28704P3HIGHCVSS 8.8fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28704 [HIGH] CVE-2021-28704: xen - PoD operations on misaligned GFNs T[his CNA information record relates to multip...
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pa
debian
CVE-2021-28708P3HIGHCVSS 8.8fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28708 [HIGH] CVE-2021-28708: xen - PoD operations on misaligned GFNs T[his CNA information record relates to multip...
PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pa
debian
CVE-2022-33745P3HIGHCVSS 8.8fixed in xen 4.16.2-1 (bookworm)2022
CVE-2022-33745 [HIGH] CVE-2022-33745: xen - insufficient TLB flush for x86 PV guests in shadow mode For migration as well as...
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable
debian
CVE-2023-34325P3HIGHCVSS 7.8fixed in xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)2023
CVE-2023-34325 [HIGH] CVE-2023-34325: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains parsing code for several filesystems, most of them based on grub-legacy code. libfsimage is used by pygrub to inspect guest disks. Pygrub runs as the same user as the toolstack (root in a priviledged domain). At least one i
debian
CVE-2017-10917P3CRITICALCVSS 9.1fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10917 [CRITICAL] CVE-2017-10917: xen - Xen through 4.8.x does not validate the port numbers of polled event channel por...
Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed i
debian
CVE-2015-8555P3HIGHCVSS 8.6fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-8555 [HIGH] CVE-2015-8555: xen - Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and ...
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
fo
debian
CVE-2017-12137P3HIGHCVSS 8.8fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-12137 [HIGH] CVE-2017-12137: xen - arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges v...
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
debian
CVE-2020-29481P3HIGHCVSS 8.8fixed in xen 4.14.0+88-g1d1d1f5391-1 (bookworm)2020
CVE-2020-29481 [HIGH] CVE-2020-29481: xen - An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes a...
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entrie
debian
CVE-2022-42335P3HIGHCVSS 7.8fixed in xen 4.17.1+2-gb773c48e36-1 (bookworm)2022
CVE-2022-42335 [HIGH] CVE-2022-42335: xen - x86 shadow paging arbitrary pointer dereference In environments where host assis...
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for a guest with a PCI device passed through to cause th
debian
CVE-2020-11741P3HIGHCVSS 8.8fixed in xen 4.11.4-1 (bookworm)2020
CVE-2020-11741 [HIGH] CVE-2020-11741: xen - An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS use...
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the administrator, the xenoprof code uses the standard Xen shared ring structure. Unfortunately, this
debian
CVE-2024-31143P3HIGHCVSS 7.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-31143 [HIGH] CVE-2024-31143: xen - An optional feature of PCI MSI called "Multiple Message" allows a device to use ...
An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling an error path could be taken in different situations, with or without a particular lock held. This error path wrongly releases the lock even w
debian
CVE-2016-3960P3HIGHCVSS 8.8fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-3960 [HIGH] CVE-2016-3960: xen - Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS u...
Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: reso
debian