CVE-2026-42489: falha de média gravidade em Xen
domctl lock open to abuse
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.1%
probabilidade de exploração
0.1%top 100% das CVEs
exploração observada
nãonenhuma fonte reporta
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
To create and manage guests, domctl operations are used by the control
domain, a possible Xenstore domain, or by a domain controlling a
particular guest. Some of these operations may not be executed in
parallel, so a system-wide lock is used. The way that lock is acquired
is, however, not providing any fairness. This is CVE-2026-42489.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking. This is
CVE-2026-42490.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Produtos afetados
Xen · XenCVEs relacionadas — Xen
No mesmo produto, das mais perigosas para as menos.
CVE-2024-31142HIGHx86: Incorrect logic for BTC/SRSO mitigationsEPSS 17.4%CVE-2024-2201MEDIUMCVE-2024-2201EPSS 8.8%CVE-2023-46842MEDIUMx86 HVM hypercalls may trigger Xen bug checkEPSS 8.5%CVE-2024-2193MEDIUMSpeculative Race Condition impacts modern CPU architectures that support speculative execution, also known as GhostRace.EPSS 1.3%CVE-2023-46839MEDIUMpci: phantom functions assigned to incorrect contextsEPSS 0.8%CVE-2025-1713HIGHdeadlock potential with VT-d and legacy PCI device pass-throughEPSS 0.8%