← Back

Xen

xen

494 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Xen
xen
Xapi
xapi
Qemu
qemu
Xen Unstable
xen-unstable

CVEs (494)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Qemu
RedhatXen
3Enterprise Linux
QemuXen
May 6, 2026
Apr 1, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted S...Show more
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.Show less
1Xen
1Xen
May 6, 2026
Mar 28, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The HVMOP_set_mem_access HVM control operations in Xen 4.1.x for 32-bit and 4.1.x through 4.4.x for 64-bit allow local guest administrators to cause a denial of service (CPU consumption) by leveraging access to certain s...Show more
The HVMOP_set_mem_access HVM control operations in Xen 4.1.x for 32-bit and 4.1.x through 4.4.x for 64-bit allow local guest administrators to cause a denial of service (CPU consumption) by leveraging access to certain service domains for HVM guests and a large input.Show less
1Xen
1Xen
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local use...Show more
Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors.Show less
1Xen
1Xen
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
8.3 HIGH· v2
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests...Show more
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service (host or guest malfunction) or possibly gain privileges via unspecified vectors.Show less
1Xen
1Xen
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to ca...Show more
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.Show less
2Qemu
Xen
2Qemu
Xen
Apr 29, 2026
Jan 19, 2014
N/A· v4
N/A· v3
2.7 LOW· v2
The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vector...Show more
The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.Show less
1Xen
1Xen
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service...Show more
Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified vectors.Show less
1Xen
1Xen
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that causes the VM to exit in one thread with a different instruction in a differ...Show more
The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that causes the VM to exit in one thread with a different instruction in a different thread.Show less
1Xen
1Xen
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
7.7 HIGH· v2
The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.
1Xen
1Xen
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
2Redhat
Xen
4Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+1 more
Apr 29, 2026
Dec 27, 2013
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction.
1Xen
1Xen
Apr 29, 2026
Dec 24, 2013
N/A· v4
N/A· v3
5.2 MEDIUM· v2
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application r...Show more
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.Show less
1Xen
1Xen
Apr 29, 2026
Dec 24, 2013
N/A· v4
N/A· v3
5.2 MEDIUM· v2
The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of ser...Show more
The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).Show less
1Xen
1Xen
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspecified errors occur, which causes the TLB entries to not be flushed and a...Show more
Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspecified errors occur, which causes the TLB entries to not be flushed and allows local guest administrators to cause a denial of service (host crash) or gain privileges via unspecified vectors.Show less
2Opensuse
Xen
2Opensuse
Xen
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
7.9 HIGH· v2
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or ga...Show more
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."Show less
1Xen
1Xen
Apr 29, 2026
Nov 18, 2013
N/A· v4
N/A· v3
5.7 MEDIUM· v2
Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which allows local HVM guest users to cause a denial of service (host crash) via...Show more
Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which allows local HVM guest users to cause a denial of service (host crash) via unspecified vectors related to "guest VMX instruction execution."Show less
1Xen
1Xen
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
5.2 MEDIUM· v2
The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.
2Debian
Xen
2Debian Linux
Xen
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
5.2 MEDIUM· v2
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlo...Show more
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.Show less
1Xen
1Xen
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, w...Show more
Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary code via unspecified vectors.Show less
1Xen
1Xen
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The ocaml binding for the xc_vcpu_getaffinity function in Xen 4.2.x and 4.3.x frees certain memory that may still be intended for use, which allows local users to cause a denial of service (heap corruption and crash) and...Show more
The ocaml binding for the xc_vcpu_getaffinity function in Xen 4.2.x and 4.3.x frees certain memory that may still be intended for use, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary code via unspecified vectors that trigger a (1) use-after-free or (2) double free.Show less