Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Xen — Vulnerabilities & Security Advisories 135

Browse all 135 CVE security advisories affecting Xen. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Xen serves as a foundational open-source hypervisor, enabling hardware virtualization for cloud infrastructure and enterprise server consolidation. Its architecture, which isolates guest operating systems within a privileged domain, has historically attracted diverse exploitation attempts. Security audits reveal a prevalence of remote code execution and buffer overflow vulnerabilities, often stemming from complex memory management in the virtualization layer. Additionally, privilege escalation flaws have been documented, allowing compromised guests to potentially breach the host environment. While Xen itself is robust, its integration with other software components has occasionally led to supply chain risks. Major incidents remain relatively contained compared to broader ecosystem failures, yet the sheer volume of recorded CVEs underscores the critical need for rigorous patch management. Continuous monitoring of kernel updates and strict access controls remain essential for maintaining the integrity of virtualized environments relying on this technology.

Found 124 results / 135Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-62434 PoD: Don't try to reclaim special pages — Xen--2026-07-28
CVE-2026-62433 correct buffer checks for DM_OP hypercalls — Xen--2026-07-28
CVE-2026-62432 evtchn: Race between FIFO expand and reset — Xen--2026-07-28
CVE-2026-62431 Viridian STIMER division by zero — Xen--2026-07-28
CVE-2026-62430 x86: Out-of-bounds read in vRTC emulation — Xen--2026-07-28
CVE-2026-62429 vNUMA domain cleanup may race other operations — Xen--2026-07-28
CVE-2026-62435 grant-table: version change racing with other operations — Xen--2026-07-28
CVE-2026-62436 grant-table: version change racing with other operations — Xen--2026-07-28
CVE-2026-62428 grant-table: type confusion in grant-copy — Xen--2026-07-28
CVE-2026-62427 sysctl and platform-op locks open to abuse — Xen--2026-07-28
CVE-2026-62426 sysctl and platform-op locks open to abuse — Xen--2026-07-28
CVE-2026-42494 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-42495 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-62423 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-62424 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-62425 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-42492 vIRQ event channel binding may break Xenstore — Xen--2026-07-28
CVE-2026-42493 x86 shadow paging is deprecated — Xen--2026-07-28
CVE-2026-42488 x86: mismatched mapcache metadata — Xen--2026-06-18
CVE-2026-42489 domctl lock open to abuse — Xen--2026-06-18
CVE-2026-42490 domctl lock open to abuse — Xen--2026-06-18
CVE-2026-42487 x86 HVM I/O port list traversal — Xen--2026-06-18
CVE-2026-23558 grant table v2 race in status page mapping — Xen--2026-05-19
CVE-2026-23557 Xenstored DoS via XS_RESET_WATCHES command — Xen--2026-05-19
CVE-2026-23555 Xenstored DoS by unprivileged domain — Xen 7.7AIHighAI2026-03-23
CVE-2026-23554 Use after free of paging structures in EPT — Xen 6.8AIMediumAI2026-03-23
CVE-2026-23553 x86: incomplete IBPB for vCPU isolation — Xen 7.5AIHighAI2026-01-28
CVE-2025-58150 x86: buffer overrun with shadow paging + tracing — Xen 8.8AIHighAI2026-01-28
CVE-2025-58149 Incorrect removal of permissions on PCI device unplug — Xen 9.1 -2025-10-31
CVE-2025-58148 x86: Incorrect input sanitisation in Viridian hypercalls — Xen 7.8 -2025-10-31

This page lists every published CVE security advisory associated with Xen. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.