Lucene search

K

Xen Security Vulnerabilities

cve
cve

CVE-2016-2270

Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.

6.8CVSS

6.8AI Score

0.005EPSS

2016-02-19 04:59 PM
42
cve
cve

CVE-2016-2271

VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.

5.5CVSS

6.1AI Score

0.001EPSS

2016-02-19 04:59 PM
37
cve
cve

CVE-2016-3157

The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain sensitive information by leveraging I/O port access...

7.8CVSS

5.9AI Score

0.001EPSS

2016-04-12 04:59 PM
64
cve
cve

CVE-2016-3158

The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE:...

3.8CVSS

6AI Score

0.001EPSS

2016-04-13 04:59 PM
40
cve
cve

CVE-2016-3159

The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NO...

3.8CVSS

6AI Score

0.001EPSS

2016-04-13 04:59 PM
47
cve
cve

CVE-2016-3960

Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.

8.8CVSS

8.5AI Score

0.001EPSS

2016-04-19 02:59 PM
47
cve
cve

CVE-2016-3961

Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.

5.5CVSS

5.6AI Score

0.001EPSS

2016-04-15 02:59 PM
60
cve
cve

CVE-2016-4480

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

8.4CVSS

8.2AI Score

0.002EPSS

2016-05-18 02:59 PM
36
cve
cve

CVE-2016-4962

The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.

6.7CVSS

6.7AI Score

0.0004EPSS

2016-06-07 02:06 PM
37
cve
cve

CVE-2016-4963

The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.

4.7CVSS

5.1AI Score

0.001EPSS

2016-06-07 02:06 PM
38
cve
cve

CVE-2016-5242

The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS crash) by creating concurrent domains and holding references to them, related to VMID exhaustion.

5.6CVSS

5.6AI Score

0.001EPSS

2016-06-07 02:06 PM
34
cve
cve

CVE-2016-6258

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

8.8CVSS

6.8AI Score

0.001EPSS

2016-08-02 04:59 PM
51
cve
cve

CVE-2016-6259

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

6.2CVSS

6AI Score

0.002EPSS

2016-08-02 04:59 PM
33
cve
cve

CVE-2016-7092

The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.

8.2CVSS

6.4AI Score

0.001EPSS

2016-09-21 02:25 PM
44
cve
cve

CVE-2016-7093

Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.

8.2CVSS

6.6AI Score

0.001EPSS

2016-09-21 02:25 PM
32
cve
cve

CVE-2016-7094

Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update.

4.1CVSS

5.4AI Score

0.001EPSS

2016-09-21 02:25 PM
41
cve
cve

CVE-2016-7154

Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.

6.7CVSS

7.1AI Score

0.001EPSS

2016-09-21 02:25 PM
28
cve
cve

CVE-2016-7777

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

6.3CVSS

6AI Score

0.001EPSS

2016-10-07 02:59 PM
49
cve
cve

CVE-2016-9377

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

5.5CVSS

5.8AI Score

0.001EPSS

2017-02-22 04:59 PM
25
cve
cve

CVE-2016-9378

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.

5.5CVSS

5.9AI Score

0.001EPSS

2017-02-22 04:59 PM
27
cve
cve

CVE-2016-9379

The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file.

7.9CVSS

7.2AI Score

0.001EPSS

2017-01-23 09:59 PM
45
cve
cve

CVE-2016-9380

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.

7.5CVSS

7.2AI Score

0.001EPSS

2017-01-23 09:59 PM
45
cve
cve

CVE-2016-9382

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.

7.8CVSS

7.3AI Score

0.001EPSS

2017-01-23 09:59 PM
45
cve
cve

CVE-2016-9383

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.

8.8CVSS

7.8AI Score

0.001EPSS

2017-01-23 09:59 PM
41
cve
cve

CVE-2016-9384

Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.

6.5CVSS

6.3AI Score

0.001EPSS

2017-02-22 04:59 PM
23
cve
cve

CVE-2016-9385

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.

6CVSS

6.1AI Score

0.001EPSS

2017-01-23 09:59 PM
45
cve
cve

CVE-2016-9386

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.

7.8CVSS

7.3AI Score

0.001EPSS

2017-01-23 09:59 PM
51
cve
cve

CVE-2016-9815

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort.

6.5CVSS

6.1AI Score

0.001EPSS

2017-02-27 10:59 PM
26
cve
cve

CVE-2016-9816

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.

6.5CVSS

6AI Score

0.001EPSS

2017-02-27 10:59 PM
24
cve
cve

CVE-2016-9817

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.

6.5CVSS

6.1AI Score

0.001EPSS

2017-02-27 10:59 PM
24
cve
cve

CVE-2016-9818

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.

6.5CVSS

6.1AI Score

0.001EPSS

2017-02-27 10:59 PM
28
cve
cve

CVE-2016-9932

CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.

3.3CVSS

4.8AI Score

0.001EPSS

2017-01-26 03:59 PM
45
cve
cve

CVE-2017-10912

Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

10CVSS

6.8AI Score

0.005EPSS

2017-07-05 01:29 AM
57
cve
cve

CVE-2017-10913

The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.

9.8CVSS

6.9AI Score

0.008EPSS

2017-07-05 01:29 AM
53
cve
cve

CVE-2017-10914

The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

8.1CVSS

7.2AI Score

0.012EPSS

2017-07-05 01:29 AM
49
cve
cve

CVE-2017-10915

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

9CVSS

6.8AI Score

0.007EPSS

2017-07-05 01:29 AM
58
cve
cve

CVE-2017-10916

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

7.5CVSS

7.3AI Score

0.003EPSS

2017-07-05 01:29 AM
45
cve
cve

CVE-2017-10917

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

9.1CVSS

7.1AI Score

0.005EPSS

2017-07-05 01:29 AM
59
cve
cve

CVE-2017-10918

Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.

10CVSS

6.9AI Score

0.009EPSS

2017-07-05 01:29 AM
50
cve
cve

CVE-2017-10919

Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

6.5CVSS

6.2AI Score

0.003EPSS

2017-07-05 01:29 AM
49
cve
cve

CVE-2017-10920

The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka X...

10CVSS

6.7AI Score

0.006EPSS

2017-07-05 01:29 AM
57
cve
cve

CVE-2017-10921

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

10CVSS

6.8AI Score

0.006EPSS

2017-07-05 01:29 AM
61
cve
cve

CVE-2017-10922

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.

7.5CVSS

6.7AI Score

0.005EPSS

2017-07-05 01:29 AM
48
cve
cve

CVE-2017-10923

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.

6.5CVSS

6.2AI Score

0.003EPSS

2017-07-05 01:29 AM
34
cve
cve

CVE-2017-12134

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability ca...

8.8CVSS

7.3AI Score

0.001EPSS

2017-08-24 02:29 PM
120
2
cve
cve

CVE-2017-12135

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

8.8CVSS

6.4AI Score

0.001EPSS

2017-08-24 02:29 PM
70
cve
cve

CVE-2017-12136

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

7.8CVSS

6.4AI Score

0.001EPSS

2017-08-24 02:29 PM
62
cve
cve

CVE-2017-12137

arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

8.8CVSS

6.1AI Score

0.001EPSS

2017-08-24 02:29 PM
64
cve
cve

CVE-2017-12855

Xen maintains the GTF {read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the...

6.5CVSS

6.7AI Score

0.001EPSS

2017-08-15 04:29 PM
48
cve
cve

CVE-2017-14316

A parameter verification issue was discovered in Xen through 4.9.x. The function alloc_heap_pages allows callers to specify the first NUMA node that should be used for allocations through the memflags parameter; the node is extracted using the MEMF_get_node macro. While the function checks to see i...

8.8CVSS

6.5AI Score

0.001EPSS

2017-09-12 03:29 PM
54
Total number of security vulnerabilities481