Back to overview

CVE-2026-42492

HIGH
7.5
CVSS 3.1
Description
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.

Metadata

CVE ID
CVE-2026-42492
State
PUBLISHED
Assigner
XEN
Reserved
2026-04-27 14:20 UTC
Published
2026-07-28 12:31 UTC
Last updated
2026-07-28 16:33 UTC
Primary CWE
CWE-459
CWE-459 Incomplete Cleanup
Vendor / Product
Xen / Xen
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Xen Xen consult Xen advisory XSA-496
Weakness (CWE)
CWESourceDescription
CWE-459 adp CWE-459 Incomplete Cleanup
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.5 HIGH 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview