Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 9 of 23
CVE-2017-15589P4MEDIUMCVSS 6.5fixed in xen 4.8.2+xsa245-0+deb9u1 (bookworm)2017
CVE-2017-15589 [MEDIUM] CVE-2017-15589: xen - An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to ...
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb
debian
CVE-2014-9030P4LOWCVSS 7.1fixed in xen 4.4.1-4 (bookworm)2014
CVE-2014-9030 [HIGH] CVE-2014-9030: xen - The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not ...
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
Scope: local
bookworm: resolved (fixed in 4.4.1-4)
bullseye: resolved (fixed in 4.4.1-4)
forky: resolved (fixed in 4.4.1-4)
sid:
debian
CVE-2022-21123P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21123 [MEDIUM] CVE-2022-21123: intel-microcode - Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may...
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in 3.20220510.1)
t
debian
CVE-2013-2072P4LOWCVSS 7.4fixed in xen 4.2.2-1 (bookworm)2013
CVE-2013-2072 [HIGH] CVE-2013-2072: xen - Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4...
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
Scope: local
bookworm: resolved (fixed in 4.2.2-1)
bullseye: resolved (fix
debian
CVE-2022-21166P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21166 [MEDIUM] CVE-2022-21166: intel-microcode - Incomplete cleanup in specific special register write operations for some Intel(...
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed i
debian
CVE-2015-2151P4HIGHCVSS 7.2fixed in xen 4.4.1-8 (bookworm)2015
CVE-2015-2151 [HIGH] CVE-2015-2151: xen - The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment ove...
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-8)
bullseye: resolved (fixe
debian
CVE-2022-33742P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-33742 [HIGH] CVE-2022-33742: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult...
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2022-26365P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-26365 [HIGH] CVE-2022-26365: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult...
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2022-33741P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-33741 [HIGH] CVE-2022-33741: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult...
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2022-33740P4HIGHCVSS 7.1fixed in linux 5.18.14-1 (bookworm)2022
CVE-2022-33740 [HIGH] CVE-2022-33740: linux - Linux disk/nic frontends data leaks T[his CNA information record relates to mult...
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sh
debian
CVE-2017-10923P4MEDIUMCVSS 6.5fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-10923 [MEDIUM] CVE-2017-10923: xen - Xen through 4.8.x does not validate a vCPU array index upon the sending of an SG...
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: reso
debian
CVE-2022-42327P4HIGHCVSS 7.1fixed in xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)2022
CVE-2022-42327 [HIGH] CVE-2022-42327: xen - x86: unintended memory sharing between guests On Intel systems that support the ...
x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared page bypasses the expected isolation that should exist between two guests.
Scope: local
bookworm: resolved (fixed in 4.16.2+90-g0d39a6
debian
CVE-2019-17342P4HIGHCVSS 7.0fixed in xen 4.11.1+92-g6c33308a8d-1 (bookworm)2019
CVE-2019-17342 [HIGH] CVE-2019-17342: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race condition that arose when XENMEM_exchange was introduced.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d
debian
CVE-2019-19579P4MEDIUMCVSS 6.8fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-19579 [MEDIUM] CVE-2019-19579: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guest
debian
CVE-2024-45818P4MEDIUMCVSS 6.5fixed in xen 4.17.5+23-ga4e5191dc0-1 (bookworm)2024
CVE-2024-45818 [MEDIUM] CVE-2024-45818: xen - The hypervisor contains code to accelerate VGA memory accesses for HVM guests, w...
The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" mode. Locking involved there has an unusual discipline, leaving a lock acquired past the return from the function that acquired it. This behavior results in a problem when emulating an instruction with two memory accesses, both of which touch VGA memo
debian
CVE-2014-7188P4HIGHCVSS 8.3fixed in xen 4.4.1-3 (bookworm)2014
CVE-2014-7188 [HIGH] CVE-2014-7188: xen - The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4...
The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-3)
bullseye: resolved (fixed in 4.4.1-3)
forky:
debian
CVE-2022-21125P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21125 [MEDIUM] CVE-2022-21125: intel-microcode - Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processor...
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in 3.20220510
debian
CVE-2019-11135P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20191112.1 (bookworm)2019
CVE-2019-11135 [MEDIUM] CVE-2019-11135: intel-microcode - TSX Asynchronous Abort condition on some CPUs utilizing speculative execution ma...
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Scope: local
bookworm: resolved (fixed in 3.20191112.1)
bullseye: resolved (fixed in 3.20191112.1)
forky: resolved (fixed in 3.20191112.1)
sid: resolved (fixed in 3.
debian
CVE-2015-7835P4HIGHCVSS 7.2fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7835 [HIGH] CVE-2015-7835: xen - The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not pro...
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
debian
CVE-2022-26364P4MEDIUMCVSS 6.7fixed in xen 4.16.2-1 (bookworm)2022
CVE-2022-26364 [MEDIUM] CVE-2022-26364: xen - x86 pv: Insufficient care with non-coherent mappings T[his CNA information recor...
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have
debian