[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions.
Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service.
1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state.
2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Aug 22, 2024 | Jan 5, 2024 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Jan 5, 2024 |
| Dell Powerstore Dsa2024120 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Mar 26, 2024 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Sep 23, 2024 | Jan 5, 2024 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-develUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-tools-domuUpgrade xen-toolsUpgrade xen | Oct 13, 2023 | Oct 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub