Xen

Xen

512 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 05.01.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:24

In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is destroyed. This allows guest OS administrators to cause a denial of servic...

  • EPSS 0.35%
  • Veröffentlicht 12.12.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging an incorrect mask for reference-count overflow checking in shadow mode.

  • EPSS 0.35%
  • Veröffentlicht 12.12.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling for reference counting in shadow mode.

  • EPSS 0.36%
  • Veröffentlicht 12.12.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mode are in place, because of an incorrect assertion related to M2P.

  • EPSS 0.36%
  • Veröffentlicht 12.12.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) or gain host OS privileges in shadow mode by mapping a certain auxiliary page.

  • EPSS 0.44%
  • Veröffentlicht 28.11.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors.

  • EPSS 0.43%
  • Veröffentlicht 28.11.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) P...

  • EPSS 0.36%
  • Veröffentlicht 28.11.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled.

  • EPSS 2.81%
  • Veröffentlicht 30.10.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy ...

  • EPSS 0.33%
  • Veröffentlicht 18.10.2017 08:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.