Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 5 of 23
CVE-2022-26360P3HIGHCVSS 7.8fixed in xen 4.16.1-1 (bookworm)2022
CVE-2022-26360 [HIGH] CVE-2022-26360: xen - IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. The
debian
CVE-2022-26361P3HIGHCVSS 7.8fixed in xen 4.16.1-1 (bookworm)2022
CVE-2022-26361 [HIGH] CVE-2022-26361: xen - IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. The
debian
CVE-2022-26358P3HIGHCVSS 7.8fixed in xen 4.16.1-1 (bookworm)2022
CVE-2022-26358 [HIGH] CVE-2022-26358: xen - IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. The
debian
CVE-2022-26359P3HIGHCVSS 7.8fixed in xen 4.16.1-1 (bookworm)2022
CVE-2022-26359 [HIGH] CVE-2022-26359: xen - IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. The
debian
CVE-2023-34322P3HIGHCVSS 7.8fixed in xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)2023
CVE-2023-34322 [HIGH] CVE-2023-34322: xen - For migration as well as to work around kernels unaware of L1TF (see XSA-273), P...
For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen itself needs to be mapped when PV guests run, Xen and shadowed PV guests run directly the respective shadow page tables. For 64-bit PV guests this means running on the shadow of the guest root page table. In the course of dealing with shor
debian
CVE-2025-1713P3HIGHCVSS 7.5fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-1713 [HIGH] CVE-2025-1713: xen - When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X...
When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This can lead to a deadlock.
Scope: local
bookworm: resolved (fixed in 4.17.5+72-g01140da4e8-1)
bullseye: open
forky: resolved (f
debian
CVE-2025-58144P3HIGHCVSS 7.5fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58144 [HIGH] CVE-2025-58144: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144.
debian
CVE-2025-58145P3HIGHCVSS 7.5fixed in xen 4.17.5+72-g01140da4e8-1 (bookworm)2025
CVE-2025-58145 [HIGH] CVE-2025-58145: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144.
debian
CVE-2024-45817P3HIGHCVSS 7.3fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-45817 [HIGH] CVE-2024-45817: xen - In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error c...
In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can opt to receive an interrupt when a new error occurs. It is possible to configure the error interrupt with an illegal vector, which generates an error when an error interrupt is raised. This case causes Xen to recurse throug
debian
CVE-2016-9383P3HIGHCVSS 8.8fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-9383 [HIGH] CVE-2016-9383: xen - Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to mod...
Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
fo
debian
CVE-2018-10982P3HIGHCVSS 8.8fixed in xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm)2018
CVE-2018-10982 [HIGH] CVE-2018-10982: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to...
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
Scope: local
bookworm: resolved (fixed in 4.8.3+xsa262
debian
CVE-2017-14319P3HIGHCVSS 8.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-14319 [HIGH] CVE-2017-14319: xen - A grant unmapping issue was discovered in Xen through 4.9.x. When removing or re...
A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.
Scope: local
b
debian
CVE-2021-27379P3HIGHCVSS 8.8fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2021
CVE-2021-27379 [HIGH] CVE-2021-27379: xen - An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS u...
An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush, and thus IOMMU updates were not always correct. NOTE: this issue exists because of an incomplete fix for CVE-2020-15565.
debian
CVE-2015-8550P3HIGHCVSS 8.2fixed in linux 4.3.3-3 (bookworm)2015
CVE-2015-8550 [HIGH] CVE-2015-8550: linux - Xen, when used on a system providing PV backends, allows local guest OS administ...
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Scope: local
bookworm: resolved (fixed in 4.3.3-3)
bullseye: resolved (fixed in 4.3.3-3)
forky: resolved (fixed in 4.3.3-3)
s
debian
CVE-2022-42330P3HIGHCVSS 7.5fixed in xen 4.17.0+24-g2f8851c37f-2 (bookworm)2022
CVE-2022-42330 [HIGH] CVE-2022-42330: xen - Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset...
Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libxl based Xen toolstack will normally perform a XS_RELEASE Xenstore operation. Due to a bug in xenstored this can result in a crash of xenstored. Any other use of XS_RELEASE will have the same impact.
Scope: local
bookworm: resolved (fixed in 4.17.0+24-g
debian
CVE-2016-9382P3HIGHCVSS 7.8fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-9382 [HIGH] CVE-2016-9382: xen - Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows l...
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed
debian
CVE-2016-9386P3HIGHCVSS 7.8fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-9386 [HIGH] CVE-2016-9386: xen - The x86 emulator in Xen does not properly treat x86 NULL segments as unusable wh...
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8.0-1)
sid: resolved (fixed in 4.8.0-1)
tri
debian
CVE-2018-19962P3HIGHCVSS 7.8fixed in xen 4.11.1-1 (bookworm)2018
CVE-2018-19962 [HIGH] CVE-2018-19962: xen - An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly all...
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
Scope: local
bookworm: resolved (fixed in 4.11.1-1)
bullseye: resolved (fixed in 4.11.1-1)
forky: resolved (fixed in 4.11.1-1)
sid: resolved (fixed in 4.11.1-1)
trixie: resolv
debian
CVE-2018-19961P3HIGHCVSS 7.8fixed in xen 4.11.1-1 (bookworm)2018
CVE-2018-19961 [HIGH] CVE-2018-19961: xen - An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly all...
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
Scope: local
bookworm: resolved (fixed in 4.11.1-1)
bullseye: resolved (fixed in 4.11.1-1)
forky: resolved (fixed in 4.11.1-1)
sid: resolved (fixed in 4.11.1-1)
trixie: resolv
debian
CVE-2020-25595P3HIGHCVSS 7.8fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-25595 [HIGH] CVE-2020-25595: xen - An issue was discovered in Xen through 4.14.x. The PCI passthrough code improper...
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be able to affect these registers, experience shows that it's very common f
debian