Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 8 of 23
CVE-2024-2201P4MEDIUMCVSS 4.7fixed in linux 6.1.85-1 (bookworm)2024
CVE-2024-2201 [MEDIUM] CVE-2024-2201: linux - A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deploy...
A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.
Scope: local
bookworm: resolved (fixed in 6.1.85-1)
bullseye: open
forky: resolved (fixed in 6.8.9-1)
sid: resolved (fixed in 6.8.9-1)
trixie: resolved (fixed in 6.8.9-1)
debian
CVE-2019-18420P4MEDIUMCVSS 6.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-18420 [MEDIUM] CVE-2019-18420: xen - An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling for a bad format character was done using BUG(), which crashes Xen. One path, via the VCPUO
debian
CVE-2019-19577P4HIGHCVSS 7.2fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19577 [HIGH] CVE-2019-19577: xen - An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS user...
An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically adapt the number of levels of pagetables (the pagetable height) in the IOMMU according to th
debian
CVE-2021-28690P4MEDIUMCVSS 6.5fixed in xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)2021
CVE-2021-28690 [MEDIUM] CVE-2021-28690: xen - x86: TSX Async Abort protections not restored after S3 This issue relates to the...
x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for details. Mitigating TAA by disabling TSX (the default and preferred option) requires selecting a non-default setting in MSR_TSX_CTRL. This setting isn't restored after S3 suspe
debian
CVE-2013-6375P4HIGHCVSS 7.9fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-6375 [HIGH] CVE-2013-6375: xen - Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properl...
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (f
debian
CVE-2018-3620P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20180703.1 (bookworm)2018
CVE-2018-3620 [MEDIUM] CVE-2018-3620: intel-microcode - Systems with microprocessors utilizing speculative execution and address transla...
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fixed in 3.20180703.1)
for
debian
CVE-2011-1898P4HIGHCVSS 7.4fixed in xen 4.1.1-1 (bookworm)2011
CVE-2011-1898 [HIGH] CVE-2011-1898: xen - Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel V...
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
Scope: local
bookworm: resolved (fixed in 4.1.1-1)
bullseye: resolved (fixed in 4.1.1-1)
forky: resolve
debian
CVE-2015-5166P4HIGHCVSS 7.2fixed in qemu 1:2.4+dfsg-1a (bookworm)2015
CVE-2015-5166 [HIGH] CVE-2015-5166: qemu - Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completel...
Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-1a)
bullseye: resolved (fixed in 1:2.4+dfsg-1a)
forky: resolved (fixed in 1:2.4+dfsg-1a)
sid: resolved (fixed in 1:2.
debian
CVE-2020-25599P4HIGHCVSS 7.0fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-25599 [HIGH] CVE-2020-25599: xen - An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race con...
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be
debian
CVE-2022-42320P4HIGHCVSS 7.0fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42320 [HIGH] CVE-2022-42320: xen - Xenstore: Guests can get access to Xenstore nodes of deleted domains Access righ...
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time w
debian
CVE-2016-7777P4MEDIUMCVSS 6.3fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-7777 [MEDIUM] CVE-2016-7777: xen - Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows lo...
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in
debian
CVE-2011-4111P4MEDIUMCVSS 6.8fixed in qemu 0.15.1+dfsg-2 (bookworm)2011
CVE-2011-4111 [MEDIUM] CVE-2011-4111: qemu - Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-...
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Scope: local
bookworm: resolved (fixed in 0.15.1+dfsg-2)
bullseye: resolved (fixed in 0.15.1+dfsg-2)
forky:
debian
CVE-2012-3515P4HIGHCVSS 7.2fixed in qemu 1.1.2+dfsg-1 (bookworm)2012
CVE-2012-3515 [HIGH] CVE-2012-3515: qemu - Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certai...
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Scope: local
bookworm: resolved (fixed in 1.1.2+dfsg-1)
bullseye: resolved (fixed in 1.1.2+dfsg-1)
fork
debian
CVE-2013-4344P4LOWCVSS 7.2fixed in qemu 1.6.0+dfsg-2 (bookworm)2013
CVE-2013-4344 [HIGH] CVE-2013-4344: qemu - Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI ...
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Scope: local
bookworm: resolved (fixed in 1.6.0+dfsg-2)
bullseye: resolved (fixed in 1.6.0+dfsg-2)
forky: resolved (fixed in 1.6.0+dfsg-2)
sid: resolved (
debian
CVE-2017-10919P4MEDIUMCVSS 6.5fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10919 [MEDIUM] CVE-2017-10919: xen - Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS ...
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+de
debian
CVE-2021-28692P4HIGHCVSS 7.1fixed in xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)2021
CVE-2021-28692 [HIGH] CVE-2021-28692: xen - inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands iss...
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some
debian
CVE-2021-28703P4HIGHCVSS 7.0fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2021
CVE-2021-28703 [HIGH] CVE-2021-28703: xen - grant table v2 status pages may remain accessible after de-allocation (take two)...
grant table v2 status pages may remain accessible after de-allocation (take two) Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages requir
debian
CVE-2020-27672P4HIGHCVSS 7.0fixed in xen 4.14.0+80-gd101b417b7-1 (bookworm)2020
CVE-2020-27672 [HIGH] CVE-2020-27672: xen - An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cau...
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
Scope: local
bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1)
bullseye: resolved (fixed in 4.14.0+80-gd1
debian
CVE-2022-26357P4HIGHCVSS 7.0fixed in xen 4.16.1-1 (bookworm)2022
CVE-2022-26357 [HIGH] CVE-2022-26357: xen - race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardw...
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked
debian
CVE-2019-18424P4MEDIUMCVSS 6.8fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-18424 [MEDIUM] CVE-2019-18424: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the devic
debian