Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 6 of 23
CVE-2017-17563P3HIGHCVSS 7.8fixed in xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm)2017
CVE-2017-17563 [HIGH] CVE-2017-17563: xen - An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a ...
An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging an incorrect mask for reference-count overflow checking in shadow mode.
Scope: local
bookworm: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
bullseye: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+
debian
CVE-2020-11739P3HIGHCVSS 7.8fixed in xen 4.11.4-1 (bookworm)2020
CVE-2020-11739 [HIGH] CVE-2020-11739: xen - An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause ...
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In other words, the unlo
debian
CVE-2021-28697P3HIGHCVSS 7.8fixed in xen 4.14.3-1 (bookworm)2021
CVE-2021-28697 [HIGH] CVE-2021-28697: xen - grant table v2 status pages may remain accessible after de-allocation Guest get ...
grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages requires that the
debian
CVE-2016-9380P3HIGHCVSS 7.5fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-9380 [HIGH] CVE-2016-9380: xen - The pygrub boot loader emulator in Xen, when nul-delimited output format is requ...
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8.0-1)
sid: resolved (
debian
CVE-2024-31145P3HIGHCVSS 7.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-31145 [HIGH] CVE-2024-31145: xen - Certain PCI devices in a system might be assigned Reserved Memory Regions (speci...
Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the ma
debian
CVE-2017-15592P3HIGHCVSS 8.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15592 [HIGH] CVE-2017-15592: xen - An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to ...
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because self-linear shadow mappings are mishandled for translated guests.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved (fixed in 4.
debian
CVE-2017-15590P3HIGHCVSS 8.8fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15590 [HIGH] CVE-2017-15590: xen - An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to caus...
An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because MSI mapping was mishandled.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
sid: resolved (fixed
debian
CVE-2024-2193P3MEDIUMCVSS 5.7fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-2193 [MEDIUM] CVE-2024-2193: linux - A Speculative Race Condition (SRC) vulnerability that impacts modern CPU archite...
A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.
Scope: local
bookworm: open
bullseye
debian
CVE-2017-10916P3HIGHCVSS 7.5fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10916 [HIGH] CVE-2017-10916: xen - The vCPU context-switch implementation in Xen through 4.8.x improperly interacts...
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky:
debian
CVE-2017-17566P3HIGHCVSS 7.8fixed in xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm)2017
CVE-2017-17566 [HIGH] CVE-2017-17566: xen - An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause...
An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) or gain host OS privileges in shadow mode by mapping a certain auxiliary page.
Scope: local
bookworm: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
bullseye: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
forky: resolved (fixed
debian
CVE-2021-28709P3HIGHCVSS 7.8fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28709 [HIGH] CVE-2021-28709: xen - issues with partially successful P2M updates on x86 T[his CNA information record...
issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspect
debian
CVE-2021-28705P3HIGHCVSS 7.8fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28705 [HIGH] CVE-2021-28705: xen - issues with partially successful P2M updates on x86 T[his CNA information record...
issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspect
debian
CVE-2017-12136P3HIGHCVSS 7.8fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-12136 [HIGH] CVE-2017-12136: xen - Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local g...
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (
debian
CVE-2019-17341P3HIGHCVSS 7.8fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17341 [HIGH] CVE-2019-17341: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11
debian
CVE-2021-28702P3HIGHCVSS 7.6fixed in xen 4.14.3+32-g9de3671772-1 (bookworm)2021
CVE-2021-28702 [HIGH] CVE-2021-28702: xen - PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system ...
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly deassigned. The IOMMU
debian
CVE-2015-8554P3HIGHCVSS 7.5fixed in xen 4.4.0-1 (bookworm)2015
CVE-2015-8554 [HIGH] CVE-2015-8554: xen - Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen...
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
debian
CVE-2017-12135P3HIGHCVSS 8.8fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-12135 [HIGH] CVE-2017-12135: xen - Xen allows local OS guest users to cause a denial of service (crash) or possibly...
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved
debian
CVE-2018-3646P3MEDIUMCVSS 5.6fixed in intel-microcode 3.20180703.1 (bookworm)2018
CVE-2018-3646 [MEDIUM] CVE-2018-3646: intel-microcode - Systems with microprocessors utilizing speculative execution and address transla...
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fi
debian
CVE-2014-1666P3HIGHCVSS 8.3fixed in xen 4.4.0-1 (bookworm)2014
CVE-2014-1666 [HIGH] CVE-2014-1666: xen - The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x...
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service (host or guest malfunction) or possibly gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4
debian
CVE-2016-9379P3HIGHCVSS 7.9fixed in xen 4.8.0-1 (bookworm)2016
CVE-2016-9379 [HIGH] CVE-2016-9379: xen - The pygrub boot loader emulator in Xen, when S-expression output format is reque...
The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8
debian