Known escape exploits

Xen breakouts are tracked as Xen Security Advisories (XSA). The recurring classes are hypercall handling bugs, reference-counting and page-type confusion around grant tables and memory sharing, and flaws in the paravirtualized backend drivers in dom0. HVM guests additionally inherit the QEMU device-model escape surface.

text
Recurring Xen escape surfaces:
- Hypercall handlers (into the hypervisor)
- Grant tables and page-type / refcount handling
- PV backend drivers in dom0 (blkback, netback)
- QEMU device models (HVM guests)

Exploitation notes#

  • Whether a surface applies depends on the guest type: PV, PVH, and HVM reach different interfaces, so confirm the guest mode first.
  • Hypercall and grant-table bugs are the highest impact, landing in the hypervisor or dom0 kernel.
  • HVM device-model escapes overlap KVM and QEMU; the surface map is in Guest to host escape.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more