Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Xen — Vulnerabilities & Security Advisories 138

Browse all 138 CVE security advisories affecting Xen. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Xen serves as a foundational open-source hypervisor, enabling hardware virtualization for cloud infrastructure and enterprise server consolidation. Its architecture, which isolates guest operating systems within a privileged domain, has historically attracted diverse exploitation attempts. Security audits reveal a prevalence of remote code execution and buffer overflow vulnerabilities, often stemming from complex memory management in the virtualization layer. Additionally, privilege escalation flaws have been documented, allowing compromised guests to potentially breach the host environment. While Xen itself is robust, its integration with other software components has occasionally led to supply chain risks. Major incidents remain relatively contained compared to broader ecosystem failures, yet the sheer volume of recorded CVEs underscores the critical need for rigorous patch management. Continuous monitoring of kernel updates and strict access controls remain essential for maintaining the integrity of virtualized environments relying on this technology.

CVE ID Title CVSS Severity Published
CVE-2025-27463 WinPVDrivers: Excessive permissions on user-exposed devices — Windows PV drivers CWE-276 - - 2026-07-09
CVE-2025-27462 WinPVDrivers: Excessive permissions on user-exposed devices — Windows PV drivers CWE-276 - - 2026-07-09
CVE-2026-42488 x86: mismatched mapcache metadata — Xen - - 2026-06-18
CVE-2026-42490 domctl lock open to abuse — Xen - - 2026-06-18
CVE-2026-42489 domctl lock open to abuse — Xen - - 2026-06-18
CVE-2026-42487 x86 HVM I/O port list traversal — Xen - - 2026-06-18
CVE-2026-23558 grant table v2 race in status page mapping — Xen - - 2026-05-19
CVE-2026-23557 Xenstored DoS via XS_RESET_WATCHES command — Xen - - 2026-05-19
CVE-2026-23555 Xenstored DoS by unprivileged domain — Xen 7.7AI High AI 2026-03-23
CVE-2026-23554 Use after free of paging structures in EPT — Xen 6.8AI Medium AI 2026-03-23
CVE-2026-23553 x86: incomplete IBPB for vCPU isolation — Xen 7.5AI High AI 2026-01-28
CVE-2025-58150 x86: buffer overrun with shadow paging + tracing — Xen 8.8AI High AI 2026-01-28
CVE-2025-58149 Incorrect removal of permissions on PCI device unplug — Xen 9.1 - 2025-10-31
CVE-2025-58147 x86: Incorrect input sanitisation in Viridian hypercalls — Xen 7.8 - 2025-10-31
CVE-2025-58148 x86: Incorrect input sanitisation in Viridian hypercalls — Xen 7.8 - 2025-10-31
CVE-2025-58145 Arm issues with page refcounting — Xen 7.1AI High AI 2025-09-11
CVE-2025-58144 Arm issues with page refcounting — Xen 7.1AI High AI 2025-09-11
CVE-2025-27466 Mutiple vulnerabilities in the Viridian interface — Xen 5.1AI Medium AI 2025-09-11
CVE-2025-58143 Mutiple vulnerabilities in the Viridian interface — Xen 5.1AI Medium AI 2025-09-11
CVE-2025-58142 Mutiple vulnerabilities in the Viridian interface — Xen 5.1AI Medium AI 2025-09-11
CVE-2025-1713 deadlock potential with VT-d and legacy PCI device pass-through — Xen 6.5AI Medium AI 2025-07-17
CVE-2025-27465 x86: Incorrect stubs exception handling for flags recovery — Xen 6.2AI Medium AI 2025-07-16
CVE-2024-2201 CVE-2024-2201 — Xen 6.2AI Medium AI 2024-12-19
CVE-2024-45819 libxl leaks data to PVH guests via ACPI tables — Xen 7.1 - 2024-12-19
CVE-2024-45818 Deadlock in x86 HVM standard VGA handling — Xen 6.5 - 2024-12-19
CVE-2024-45817 x86: Deadlock in vlapic_error() — Xen 5.5AI Medium AI 2024-09-25
CVE-2024-31146 PCI device pass-through with shared resources — Xen 8.1AI High AI 2024-09-25
CVE-2024-31145 error handling in x86 IOMMU identity mapping — Xen 7.1AI High AI 2024-09-25
CVE-2024-31143 double unlock in x86 guest IRQ handling — Xen 5.5AI Medium AI 2024-07-18
CVE-2024-31142 x86: Incorrect logic for BTC/SRSO mitigations — Xen 6.2 - 2024-05-16

This page lists every published CVE security advisory associated with Xen. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.