Vulnerabilidades en Xen

143 resultados
Análisis Vexday

O hipervisor Xen acumula 111 CVEs catalogadas, com três classificadas como críticas e nenhuma atualmente registrada no catálogo CISA KEV, situando-o abaixo da média geral de exploração ativa do catálogo. A ausência de provas de conceito públicas contribui para um perfil de risco operacional contido no momento, embora o surgimento de 6 vulnerabilidades nos últimos 90 dias indique atividade contínua de descoberta que merece acompanhamento. A falha mais comum é CWE-770 (alocação de recursos sem limites adequados), padrão que em ambientes de virtualização pode ser explorado para esgotamento de recursos e impacto sobre múltiplos guests. A CVE mais perigosa atualmente rastreada é CVE-2024-31142, com escore EPSS de 0,1744, o que sugere probabilidade de exploração não desprezível e deve orientar a priorização de correções em ambientes que executam cargas de trabalho sensíveis sobre Xen.

CVE-2022-33748lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. WhiEPSS 0.3%CVE-2022-42335x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted PEPSS 0.3%CVE-2023-46840MEDIUMVT-d: Failure to quarantine devices in !HVM buildsEPSS 0.3%CVE-2022-42336LOWMishandling of guest SSBD selection on AMD hardware The current logic to set SSBD on AMD Family 17h and Hygon Family 18h processors requiresEPSS 0.3%CVE-2021-28697grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The mEPSS 0.3%CVE-2023-34321LOWarm32: The cache may not be properly cleaned/invalidatedEPSS 0.3%CVE-2022-26357race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain IDEPSS 0.3%CVE-2023-34328MEDIUMx86/AMD: Debug Mask handlingEPSS 0.3%CVE-2023-34323MEDIUMxenstored: A transaction conflict can crash C XenstoredEPSS 0.3%CVE-2023-34327MEDIUMx86/AMD: Debug Mask handlingEPSS 0.3%CVE-2022-42314MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2026-62433HIGHcorrect buffer checks for DM_OP hypercallsEPSS 0.3%CVE-2022-42313MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42317MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42311MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42318MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42316MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42315MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42312MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2023-46836MEDIUMx86: BTC/SRSO fixes not fully effectiveEPSS 0.3%