cbcvebase.

Debian Xen vulnerabilities

444 known vulnerabilities affecting debian/xen.

Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63

Vulnerabilities

Page 7 of 23
CVE-2022-29900P3MEDIUMCVSS 6.5fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-29900 [MEDIUM] CVE-2022-29900: linux - Mis-trained branch predictions for return instructions may allow arbitrary specu... Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. Scope: local bookworm: resolved (fixed in 5.18.14-1) bullseye: resolved (fixed in 5.10.136-1) forky: resolved (fixed in 5.18.14-1) sid: resolved (fixed in 5.18.14-1) trixie: resolved (fixed in 5.18.14-1)
debian
CVE-2019-19580P3HIGHCVSS 7.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19580 [HIGH] CVE-2019-19580: xen - An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to ... An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in restartable PV type change operations. Despite extensive testing and auditing, some corner cases
debian
CVE-2019-17347P3HIGHCVSS 7.8fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17347 [HIGH] CVE-2019-17347: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ... An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels). Scope: local bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1) bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-
debian
CVE-2017-17564P3HIGHCVSS 7.8fixed in xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm)2017
CVE-2017-17564 [HIGH] CVE-2017-17564: xen - An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a ... An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling for reference counting in shadow mode. Scope: local bookworm: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5) bullseye: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
debian
CVE-2020-27671P3HIGHCVSS 7.8fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-27671 [HIGH] CVE-2020-27671: xen - An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS ... An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled. Scope: local bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1) bullseye: resolved (fixed in 4.14.0+80-gd101b417b7-1) forky:
debian
CVE-2020-27670P3HIGHCVSS 7.8fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-27670 [HIGH] CVE-2020-27670: xen - An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cau... An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated. Scope: local bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1) bullseye: resolved (fixed in 4.14.0+80-gd101b417b7-1) forky: resolved (fixed
debian
CVE-2016-9381P3HIGHCVSS 7.5fixed in xen 4.4.0-1 (bookworm)2016
CVE-2016-9381 [HIGH] CVE-2016-9381: xen - Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to ga... Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability. Scope: local bookworm: resolved (fixed in 4.4.0-1) bullseye: resolved (fixed in 4.4.0-1) forky: resolved (fixed in 4.4.0-1) sid: resolved (fixed in 4.4.0-1) trixie: resolved (fixed in 4.4.0-1)
debian
CVE-2023-46842P4MEDIUMCVSS 6.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2023
CVE-2023-46842 [MEDIUM] CVE-2023-46842: xen - Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other m... Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of hypercalls takes a considerable amount of time, the hypervisor may choose to invoke a hypercal
debian
CVE-2015-4104P3HIGHCVSS 7.8fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4104 [HIGH] CVE-2015-4104: qemu - Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, ... Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolved (fixed in 1:2.3+dfsg-5) forky: resolved (fixed in 1:2.3+dfsg-5) sid: resolved (fixed in
debian
CVE-2018-18883P4HIGHCVSS 8.8fixed in xen 4.11.1-1 (bookworm)2018
CVE-2018-18883 [HIGH] CVE-2018-18883: xen - An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, all... An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted. Scope: local bookworm: resolved (fixed in 4.11.1-1) bullseye: resolved (fixed in 4.11.1-1) forky: resolved (f
debian
CVE-2016-7092P4HIGHCVSS 8.2fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-7092 [HIGH] CVE-2016-7092: xen - The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV gu... The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables. Scope: local bookworm: resolved (fixed in 4.8.0~rc3-1) bullseye: resolved (fixed in 4.8.0~rc3-1) forky: resolved (fixed in 4.8.0~rc3-1) sid: resolved (fixed in 4.8.0~rc3-1) trixie: resolved (fixed
debian
CVE-2017-10922P4HIGHCVSS 7.5fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10922 [HIGH] CVE-2017-10922: xen - The grant-table feature in Xen through 4.8.x mishandles MMIO region grant refere... The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3. Scope: local bookworm: resolved (fixed in 4.8.1-1+deb9u3) bullseye: resolved (fixed in 4.8.1-1+deb9u3) forky: resolved (fixed in 4.8.1-1+deb9u3) sid: resolved (fixed in 4.8.1-1+deb
debian
CVE-2012-0029P3MEDIUMCVSS 7.4fixed in xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm)2012
CVE-2012-0029 [HIGH] CVE-2012-0029: xen - Heap-based buffer overflow in the process_tx_desc function in the e1000 emulatio... Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets. Scope: local bookworm: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1) bullseye: resolved
debian
CVE-2016-9637P4LOWCVSS 7.5fixed in xen 4.4.0-1 (bookworm)2016
CVE-2016-9637 [HIGH] CVE-2016-9637: qemu - The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as ... The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2024-31146P4HIGHCVSS 7.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-31146 [HIGH] CVE-2024-31146: xen - When multiple devices share resources and one of them is to be passed through to... When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guaranteed without knowing internals of any of the involved guests. Therefore such a configuration cannot really be security-supported, yet making that explicit was so far missing. Resources the sh
debian
CVE-2015-5154P4HIGHCVSS 7.2fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5154 [HIGH] CVE-2015-5154: qemu - Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x an... Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands. Scope: local bookworm: resolved (fixed in 1:2.4+dfsg-1a) bullseye: resolved (fixed in 1:2.4+dfsg-1a) forky: resolved (fixed in 1:2.4+dfsg-1a)
debian
CVE-2015-0361P4HIGHCVSS 7.8fixed in xen 4.4.1-7 (bookworm)2015
CVE-2015-0361 [HIGH] CVE-2015-0361: xen - Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domain... Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown. Scope: local bookworm: resolved (fixed in 4.4.1-7) bullseye: resolved (fixed in 4.4.1-7) forky: resolved (fixed in 4.4.1-7) sid: resolved (fixed in 4.4.1-7) trixie: resolved (fixed in 4.4.1-7)
debian
CVE-2015-8341P4HIGHCVSS 7.8fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-8341 [HIGH] CVE-2015-8341: xen - The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release... The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains. Scope: local bookworm: resolved (fixed in 4.8.0~rc3-1) bullseye: resolved (fixed in
debian
CVE-2023-20588P4MEDIUMCVSS 5.5fixed in linux 6.1.52-1 (bookworm)2023
CVE-2023-20588 [MEDIUM] CVE-2023-20588: linux - A division-by-zero error on some AMD processors can potentially return speculati... A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. Scope: local bookworm: resolved (fixed in 6.1.52-1) bullseye: resolved (fixed in 5.10.197-1) forky: resolved (fixed in 6.4.13-1) sid: resolved (fixed in 6.4.13-1) trixie: resolved (fixed in 6.4.13-1)
debian
CVE-2018-19963P4HIGHCVSS 7.8fixed in xen 4.11.1-1 (bookworm)2018
CVE-2018-19963 [HIGH] CVE-2018-19963: xen - An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denia... An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled. Scope: local bookworm: resolved (fixed in 4.11.1-1) bullseye: resolved (fixed in 4.11.1-1) forky: resolved (fixed in 4.11.1-1) sid: resolved
debian
Debian Xen vulnerabilities | cvebase