Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Xen — Vulnerabilities & Security Advisories 135

Browse all 135 CVE security advisories affecting Xen. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Xen serves as a foundational open-source hypervisor, enabling hardware virtualization for cloud infrastructure and enterprise server consolidation. Its architecture, which isolates guest operating systems within a privileged domain, has historically attracted diverse exploitation attempts. Security audits reveal a prevalence of remote code execution and buffer overflow vulnerabilities, often stemming from complex memory management in the virtualization layer. Additionally, privilege escalation flaws have been documented, allowing compromised guests to potentially breach the host environment. While Xen itself is robust, its integration with other software components has occasionally led to supply chain risks. Major incidents remain relatively contained compared to broader ecosystem failures, yet the sheer volume of recorded CVEs underscores the critical need for rigorous patch management. Continuous monitoring of kernel updates and strict access controls remain essential for maintaining the integrity of virtualized environments relying on this technology.

CVE IDTitleCVSSSeverityPublished
CVE-2026-62434 PoD: Don't try to reclaim special pages — Xen--2026-07-28
CVE-2026-62433 correct buffer checks for DM_OP hypercalls — Xen--2026-07-28
CVE-2026-62432 evtchn: Race between FIFO expand and reset — Xen--2026-07-28
CVE-2026-62431 Viridian STIMER division by zero — Xen--2026-07-28
CVE-2026-62430 x86: Out-of-bounds read in vRTC emulation — Xen--2026-07-28
CVE-2026-62429 vNUMA domain cleanup may race other operations — Xen--2026-07-28
CVE-2026-62436 grant-table: version change racing with other operations — Xen--2026-07-28
CVE-2026-62435 grant-table: version change racing with other operations — Xen--2026-07-28
CVE-2026-62428 grant-table: type confusion in grant-copy — Xen--2026-07-28
CVE-2026-62426 sysctl and platform-op locks open to abuse — Xen--2026-07-28
CVE-2026-62427 sysctl and platform-op locks open to abuse — Xen--2026-07-28
CVE-2026-62424 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-62423 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-62425 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-42494 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-42495 buffer overruns in libfsimage iso9660 handling — Xen--2026-07-28
CVE-2026-42492 vIRQ event channel binding may break Xenstore — Xen--2026-07-28
CVE-2026-42493 x86 shadow paging is deprecated — Xen--2026-07-28
CVE-2026-42486 Multiple RBAC issues in XAPI — XAPICWE-250--2026-07-09
CVE-2026-23562 Multiple RBAC issues in XAPI — XAPICWE-250--2026-07-09
CVE-2026-23561 Multiple RBAC issues in XAPI — XAPICWE-250--2026-07-09
CVE-2026-23560 Multiple RBAC issues in XAPI — XAPICWE-250--2026-07-09
CVE-2026-23559 Multiple RBAC issues in XAPI — XAPICWE-250--2026-07-09
CVE-2026-23556 oxenstored keeps quota related use counts across domain destruction — oxenstoredCWE-281--2026-07-09
CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory — varstoredCWE-367--2026-07-09
CVE-2025-58146 XAPI UTF-8 string handling — XAPICWE-20--2026-07-09
CVE-2025-27464 WinPVDrivers: Excessive permissions on user-exposed devices — Windows PV driversCWE-276--2026-07-09
CVE-2025-27463 WinPVDrivers: Excessive permissions on user-exposed devices — Windows PV driversCWE-276--2026-07-09
CVE-2025-27462 WinPVDrivers: Excessive permissions on user-exposed devices — Windows PV driversCWE-276--2026-07-09
CVE-2026-42488 x86: mismatched mapcache metadata — Xen--2026-06-18

This page lists every published CVE security advisory associated with Xen. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.