Xen

Xen

479 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 31.10.2025 11:50:39
  • Zuletzt bearbeitet 04.11.2025 22:16:33

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assigned to the...

  • EPSS 0.04%
  • Veröffentlicht 31.10.2025 11:50:28
  • Zuletzt bearbeitet 04.11.2025 22:16:32

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking...

  • EPSS 0.04%
  • Veröffentlicht 31.10.2025 11:50:28
  • Zuletzt bearbeitet 04.11.2025 22:16:32

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking...

  • EPSS 0.06%
  • Veröffentlicht 11.09.2025 14:05:36
  • Zuletzt bearbeitet 04.11.2025 22:16:32

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, w...

  • EPSS 0.05%
  • Veröffentlicht 11.09.2025 14:05:36
  • Zuletzt bearbeitet 04.11.2025 22:16:32

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, w...

  • EPSS 0.06%
  • Veröffentlicht 11.09.2025 14:05:29
  • Zuletzt bearbeitet 04.11.2025 22:16:08

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL ...

  • EPSS 0.06%
  • Veröffentlicht 11.09.2025 14:05:29
  • Zuletzt bearbeitet 04.11.2025 22:16:32

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL ...

  • EPSS 0.05%
  • Veröffentlicht 11.09.2025 14:05:29
  • Zuletzt bearbeitet 04.11.2025 22:16:32

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL ...

  • EPSS 0.06%
  • Veröffentlicht 17.07.2025 13:59:46
  • Zuletzt bearbeitet 17.07.2025 21:15:50

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This...

  • EPSS 0.05%
  • Veröffentlicht 16.07.2025 09:15:23
  • Zuletzt bearbeitet 04.11.2025 22:16:08

Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which is supposed to be handled gracefully. Certain replay...