Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 4 of 23
CVE-2018-19966P3HIGHCVSS 8.8fixed in xen 4.11.1-1 (bookworm)2018
CVE-2018-19966 [HIGH] CVE-2018-19966: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
Scope: local
bookworm: resolved (fixed in 4.11
debian
CVE-2017-17045P3HIGHCVSS 8.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-17045 [HIGH] CVE-2017-17045: xen - An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain...
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixe
debian
CVE-2019-17340P3HIGHCVSS 8.8fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17340 [HIGH] CVE-2019-17340: xen - An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cau...
An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfer requests are mishandled.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
sid: resolved (fixed in
debian
CVE-2019-17346P3HIGHCVSS 8.8fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17346 [HIGH] CVE-2019-17346: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-
debian
CVE-2020-29040P3HIGHCVSS 7.8fixed in xen 4.14.0+88-g1d1d1f5391-1 (bookworm)2020
CVE-2020-29040 [HIGH] CVE-2020-29040: xen - An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to...
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error. NOTE: this issue is caused by an incorrect fix for CVE-2020-27671.
Scope: local
bookworm: resolved (fixed in 4.14.0+88-g1d1d1f5391-1)
bullseye: resolved (fixed in 4.1
debian
CVE-2022-23033P3HIGHCVSS 7.8fixed in xen 4.16.0+51-g0941d6cb-1 (bookworm)2022
CVE-2022-23033 [HIGH] CVE-2022-23033: xen - arm: guest_physmap_remove_page not removing the p2m mappings The functions to re...
arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually clear the pagetable entry if the entry doesn't have the valid bit set. It is possible to have a valid pagetable entry with
debian
CVE-2017-15588P3HIGHCVSS 7.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15588 [HIGH] CVE-2017-15588: xen - An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to e...
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
sid: resolved (fixed in 4.8
debian
CVE-2023-34326P3HIGHCVSS 7.8fixed in xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)2023
CVE-2023-34326 [HIGH] CVE-2023-34326: xen - The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.0...
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if some fields of the DTE are updated but the IOMMU TLB is not flushed. Such stale DMA mappings can point to memory ranges not owned by the guest, thus allowing access to unindented memory reg
debian
CVE-2020-15567P3HIGHCVSS 7.8fixed in xen 4.11.4+24-gddaaccbbab-1 (bookworm)2020
CVE-2020-15567 [HIGH] CVE-2020-15567: xen - An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to ...
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-atomic bitfield writes. Depending on the compiler version and optimisation flags, Xen might ex
debian
CVE-2022-42332P3HIGHCVSS 7.8fixed in xen 4.17.0+74-g3eac216e6e-1 (bookworm)2022
CVE-2022-42332 [HIGH] CVE-2022-42332: xen - x86 shadow plus log-dirty mode use-after-free In environments where host assiste...
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data structures. To migrate or snapshot guests, Xen additionally ru
debian
CVE-2021-28701P3HIGHCVSS 7.8fixed in xen 4.14.3-1 (bookworm)2021
CVE-2021-28701 [HIGH] CVE-2021-28701: xen - Another race in XENMAPSPACE_grant_table handling Guests are permitted access to ...
Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, are de-allocated when a guest switches (back) from v2 to v1. Freeing such pages requires that the hypervisor enforce that no
debian
CVE-2018-7541P3HIGHCVSS 8.8fixed in xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm)2018
CVE-2018-7541 [HIGH] CVE-2018-7541: xen - An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a...
An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.
Scope: local
bookworm: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
bullseye: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
forky: resolved (fixed in 4.8.
debian
CVE-2016-1570P3HIGHCVSS 8.5fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-1570 [HIGH] CVE-2016-1570: xen - The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x t...
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXT_MARK_SUPER or (2) MMUEXT_UNMARK_SUPER sub-op in the HYPERVISOR_mmuext_op hypercall or (3) unkn
debian
CVE-2017-15594P3HIGHCVSS 8.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15594 [HIGH] CVE-2017-15594: xen - An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users ...
An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users to cause a denial of service (hypervisor crash) or gain privileges because IDT settings are mishandled during CPU hotplugging.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
debian
CVE-2022-42309P3HIGHCVSS 8.8fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42309 [HIGH] CVE-2022-42309: xen - Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malici...
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes
debian
CVE-2017-10914P3HIGHCVSS 8.1fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10914 [HIGH] CVE-2017-10914: xen - The grant-table feature in Xen through 4.8.x has a race condition leading to a d...
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (f
debian
CVE-2016-4480P3HIGHCVSS 8.4fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-4480 [HIGH] CVE-2016-4480: xen - The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earl...
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
f
debian
CVE-2019-19583P3HIGHCVSS 7.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19583 [HIGH] CVE-2019-19583: xen - An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS user...
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the need for #DB interception. The VMX VMEntry checks do not like the exact combination of state wh
debian
CVE-2016-10013P3HIGHCVSS 7.8fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-10013 [HIGH] CVE-2016-10013: xen - Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges ...
Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8.0-1)
sid: resolved (fixed in 4.8.0-1)
trixie: resolved (fixed in 4.8.0-1)
debian
CVE-2020-25603P3HIGHCVSS 7.8fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-25603 [HIGH] CVE-2020-25603: xen - An issue was discovered in Xen through 4.14.x. There are missing memory barriers...
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a sequence is missing an appropriate memory barrier (e.g., smp_*mb()) to prevent both the compiler and CPU from re-ordering access. A ma
debian