Skip to main content

Vendor archive

xen CVEs

Beta · best-effort

495 CVEs tagged to vendor xen15 Critical, 162 High, 267 Medium, 51 Low, 0 Unrated.

CVE-2026-23558

Published May 19, 2026

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table version change from v2 to v1 i…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-23557

Published May 19, 2026

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-23555

Published Mar 23, 2026

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when ver…

CVSS 7.1 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-23554

Published Mar 23, 2026

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked r…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-23553

Published Jan 28, 2026

In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-58150

Published Jan 28, 2026

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest contro…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58149

Published Oct 31, 2025

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58148

Published Oct 31, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vC…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58147

Published Oct 31, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vC…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58145

Published Sep 11, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58144

Published Sep 11, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58143

Published Sep 11, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-58142

Published Sep 11, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27466

Published Sep 11, 2025

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-1713

Published Jul 17, 2025

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of…

CVSS 7.5 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-27465

Published Jul 16, 2025

Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-31144

Published Feb 14, 2025

For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-overview Xapi contains functionality to backup and restore me…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45819

Published Dec 19, 2024

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While act…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45818

Published Dec 19, 2024

The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" mode. Locking involved there has an unusual discipline, lea…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-45817

Published Sep 25, 2024

In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can opt to receive an interrupt w…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31146

Published Sep 25, 2024

When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31145

Published Sep 25, 2024

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-V…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31143

Published Jul 18, 2024

An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31142

Published May 16, 2024

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) u…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46842

Published May 16, 2024

Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall argu…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 495 CVEsPage 1 of 20