Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

xen — Vulnerabilities & Security Advisories 129

All 129 CVE vulnerabilities found in xen, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for Xen, the open-source type-1 hypervisor developed by Xen Project (formerly Citrix and NetScale). The collection focuses on security flaws affecting virtualization, memory management, and inter-domain communication, covering advisories published over the past decade. Readers can use this index to track the vendor’s advisory history, analyze recurring weakness classes, and review the complete vulnerability timeline for the Xen platform.

Vendor: Xen

CVE ID Title CVSS Severity Published
CVE-2026-79603 Unconditionally do TLB flushing ahead of page scrubbing - - 2026-09-08
CVE-2026-79602 x86: improper handling of HVM emulation return codes - - 2026-09-08
CVE-2026-62437 x86: DMs may cause mem leak by IRQ binding - - 2026-09-08
CVE-2026-62434 PoD: Don't try to reclaim special pages - - 2026-07-28
CVE-2026-62433 correct buffer checks for DM_OP hypercalls - - 2026-07-28
CVE-2026-62432 evtchn: Race between FIFO expand and reset - - 2026-07-28
CVE-2026-62431 Viridian STIMER division by zero - - 2026-07-28
CVE-2026-62430 x86: Out-of-bounds read in vRTC emulation - - 2026-07-28
CVE-2026-62429 vNUMA domain cleanup may race other operations - - 2026-07-28
CVE-2026-62435 grant-table: version change racing with other operations - - 2026-07-28
CVE-2026-62436 grant-table: version change racing with other operations - - 2026-07-28
CVE-2026-62428 grant-table: type confusion in grant-copy - - 2026-07-28
CVE-2026-62426 sysctl and platform-op locks open to abuse - - 2026-07-28
CVE-2026-62427 sysctl and platform-op locks open to abuse - - 2026-07-28
CVE-2026-62425 buffer overruns in libfsimage iso9660 handling - - 2026-07-28
CVE-2026-62424 buffer overruns in libfsimage iso9660 handling - - 2026-07-28
CVE-2026-62423 buffer overruns in libfsimage iso9660 handling - - 2026-07-28
CVE-2026-42494 buffer overruns in libfsimage iso9660 handling - - 2026-07-28
CVE-2026-42495 buffer overruns in libfsimage iso9660 handling - - 2026-07-28
CVE-2026-42492 vIRQ event channel binding may break Xenstore - - 2026-07-28
CVE-2026-42493 x86 shadow paging is deprecated - - 2026-07-28
CVE-2026-42488 x86: mismatched mapcache metadata - - 2026-06-18
CVE-2026-42489 domctl lock open to abuse - - 2026-06-18
CVE-2026-42490 domctl lock open to abuse - - 2026-06-18
CVE-2026-42487 x86 HVM I/O port list traversal - - 2026-06-18
CVE-2026-23558 grant table v2 race in status page mapping - - 2026-05-19
CVE-2026-23557 Xenstored DoS via XS_RESET_WATCHES command - - 2026-05-19
CVE-2026-23555 Xenstored DoS by unprivileged domain 7.7AI High AI 2026-03-23
CVE-2026-23554 Use after free of paging structures in EPT 6.8AI Medium AI 2026-03-23
CVE-2026-23553 x86: incomplete IBPB for vCPU isolation 7.5AI High AI 2026-01-28

All 129 known CVE vulnerabilities affecting xen with full Chinese analysis, references, and POCs where available.