Where
AND
-Infinity
0
Severity
5.5
Input Validation, Null Pointer Dereference
AV:A/AC:L/Au:S/C:N/I:N/A:C

The vgicdistrmmiowrite function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.

First published (updated )
Severity
5.5
AV:A/AC:L/Au:S/C:N/I:N/A:C

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.

First published (updated )
Severity
4.9
Input Validation
AV:A/AC:M/Au:S/C:P/I:P/A:P

The (1) dosend and (2) dorecv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."

First published (updated )
Severity
6.7
AV:A/AC:L/Au:S/C:P/I:P/A:C

The HVMOPsetmemtype control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.

First published (updated )
Severity
6.2
AV:A/AC:L/Au:S/C:N/I:P/A:C

Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTLEL1 register, which allows local guest users to modify the hardware timers and cause a denial of service (crash) via unspecified vectors.

First published (updated )
Severity
5.5
Null Pointer Dereference
AV:A/AC:L/Au:S/C:N/I:N/A:C

The HVMOPinjectmsi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.

First published (updated )
Severity
5.5
AV:A/AC:L/Au:S/C:N/I:N/A:C

The HVMOPinjectmsi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.

First published (updated )
Severity
7.4
AV:A/AC:M/Au:S/C:C/I:C/A:C

Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to gain privileges via unspecified vectors.

First published (updated )
Severity
3.3
Input Validation, Buffer Overflow
AV:L/AC:M/Au:N/C:P/I:N/A:P

Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which triggers a buffer overflow.

First published (updated )
Severity
1.9
Input Validation
AV:L/AC:M/Au:N/C:N/I:N/A:P

Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel.

First published (updated )
Severity
3.3
Input Validation, Buffer Overflow
AV:L/AC:M/Au:N/C:P/I:N/A:P

The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.

First published (updated )
Severity
3.3
Buffer Overflow
AV:L/AC:M/Au:N/C:P/I:N/A:P

Buffer overflow in Xen 4.4.x allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit guest kernel, related to searching for an appended DTB.

First published (updated )
Severity
2.7
Buffer Overflow
AV:A/AC:L/Au:S/C:P/I:N/A:N

Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors.

First published (updated )
Severity
2.7
Infoleak
AV:A/AC:L/Au:S/C:P/I:N/A:N

The allocdomainstruct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOPsetuptable subhypercall.

First published (updated )
Severity
6
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

An issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS users to cause a denial of service (prevent physical CPU usage) because of lock mishandling upon detection of an add-to-physmap error.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203