Vulnerabilities in Xen

143 results
Vexday analysis

O hipervisor Xen acumula 111 CVEs catalogadas, com três classificadas como críticas e nenhuma atualmente registrada no catálogo CISA KEV, situando-o abaixo da média geral de exploração ativa do catálogo. A ausência de provas de conceito públicas contribui para um perfil de risco operacional contido no momento, embora o surgimento de 6 vulnerabilidades nos últimos 90 dias indique atividade contínua de descoberta que merece acompanhamento. A falha mais comum é CWE-770 (alocação de recursos sem limites adequados), padrão que em ambientes de virtualização pode ser explorado para esgotamento de recursos e impacto sobre múltiplos guests. A CVE mais perigosa atualmente rastreada é CVE-2024-31142, com escore EPSS de 0,1744, o que sugere probabilidade de exploração não desprezível e deve orientar a priorização de correções em ambientes que executam cargas de trabalho sensíveis sobre Xen.

CVE-2022-42322Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains EPSS 0.3%CVE-2023-34325HIGHMultiple vulnerabilities in libfsimage disk handlingEPSS 0.3%CVE-2023-34326HIGHx86/AMD: missing IOMMU TLB flushingEPSS 0.3%CVE-2021-28692inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issEPSS 0.3%CVE-2021-28710certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may EPSS 0.3%CVE-2022-42309Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during EPSS 0.3%CVE-2022-33746P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. TherEPSS 0.3%CVE-2023-46835MEDIUMx86/AMD: mismatch in IOMMU quarantine page table levelsEPSS 0.3%CVE-2022-42324Oxenstored 32->31 bit integer truncation issues Integers in Ocaml are 63 or 31 bits of signed precision. The Ocaml Xenbus library takes a C EPSS 0.3%CVE-2022-42319Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quitEPSS 0.3%CVE-2022-42320Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, tEPSS 0.3%CVE-2022-42321Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting aEPSS 0.3%CVE-2022-42310Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guestEPSS 0.3%CVE-2022-33747Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-MachEPSS 0.3%CVE-2022-42331x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one EPSS 0.3%CVE-2023-46841MEDIUMx86: shadow stack vs exceptions from emulation stubsEPSS 0.3%CVE-2024-45818MEDIUMDeadlock in x86 HVM standard VGA handlingEPSS 0.3%CVE-2022-42332x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted PagEPSS 0.3%CVE-2022-42334x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabEPSS 0.3%CVE-2021-28701Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pageEPSS 0.3%