Xen breakouts are tracked as Xen Security Advisories (XSA). The recurring classes are hypercall handling bugs, reference-counting and page-type confusion around grant tables and memory sharing, and flaws in the paravirtualized backend drivers in dom0. HVM guests additionally inherit the QEMU device-model escape surface.
Recurring Xen escape surfaces:
- Hypercall handlers (into the hypervisor)
- Grant tables and page-type / refcount handling
- PV backend drivers in dom0 (blkback, netback)
- QEMU device models (HVM guests)
Exploitation notes#
- Whether a surface applies depends on the guest type: PV, PVH, and HVM reach different interfaces, so confirm the guest mode first.
- Hypercall and grant-table bugs are the highest impact, landing in the hypervisor or dom0 kernel.
- HVM device-model escapes overlap KVM and QEMU; the surface map is in Guest to host escape.