Vulnerabilidades em Xen

140 resultados
Análise Vexday

O hipervisor Xen acumula 111 CVEs catalogadas, com três classificadas como críticas e nenhuma atualmente registrada no catálogo CISA KEV, situando-o abaixo da média geral de exploração ativa do catálogo. A ausência de provas de conceito públicas contribui para um perfil de risco operacional contido no momento, embora o surgimento de 6 vulnerabilidades nos últimos 90 dias indique atividade contínua de descoberta que merece acompanhamento. A falha mais comum é CWE-770 (alocação de recursos sem limites adequados), padrão que em ambientes de virtualização pode ser explorado para esgotamento de recursos e impacto sobre múltiplos guests. A CVE mais perigosa atualmente rastreada é CVE-2024-31142, com escore EPSS de 0,1744, o que sugere probabilidade de exploração não desprezível e deve orientar a priorização de correções em ambientes que executam cargas de trabalho sensíveis sobre Xen.

CVE-2025-58144HIGHArm issues with page refcountingEPSS 0.4%CVE-2025-58149HIGHIncorrect removal of permissions on PCI device unplugEPSS 0.4%CVE-2021-28694IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corrEPSS 0.4%CVE-2021-28695IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corrEPSS 0.4%CVE-2022-26362x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. ThisEPSS 0.4%CVE-2026-62431HIGHViridian STIMER division by zeroEPSS 0.4%CVE-2021-28689x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was dEPSS 0.4%CVE-2021-28696IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corrEPSS 0.4%CVE-2025-58147HIGHx86: Incorrect input sanitisation in Viridian hypercallsEPSS 0.4%CVE-2025-58148HIGHx86: Incorrect input sanitisation in Viridian hypercallsEPSS 0.4%CVE-2021-28699inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, wheEPSS 0.4%CVE-2026-42488HIGHx86: mismatched mapcache metadataEPSS 0.4%CVE-2022-23035Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involveEPSS 0.4%CVE-2022-26360IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspEPSS 0.4%CVE-2022-26361IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspEPSS 0.4%CVE-2022-26358IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspEPSS 0.4%CVE-2021-28698long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domaEPSS 0.4%CVE-2022-26359IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspEPSS 0.3%CVE-2021-28707PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corEPSS 0.3%CVE-2022-26363x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%