Xen Multiple Vulnerabilities
Release Date: 30 Jul 2026
RISK: Medium Risk
TYPE: Operating Systems - Linux
Multiple vulnerabilities have been identified in Xen. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass and sensitive information disclosure on the targeted system.
Impact
- Denial of Service
- Information Disclosure
- Security Restriction Bypass
- Elevation of Privilege
System / Technologies affected
- CVE-2026-42492: Xen 4.21 and later are vulnerable. Xen 4.20 and earlier are not vulnerable.
- CVE-2026-42493: All x86 systems running Xen builds with
SHADOW_PAGING=yare affected. Before Xen 4.7, this control did not exist and all builds are affected. Xen 4.6 provided a separate mechanism to disable shadow paging by passingshadow-paging=non the make command line. - CVE-2026-42494: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
- CVE-2026-42495: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
- CVE-2026-62423: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
- CVE-2026-62424: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
- CVE-2026-62425: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
- CVE-2026-62426: All Xen versions from 4.0 onwards are vulnerable. Earlier versions use a different locking operation but may also be vulnerable.
- CVE-2026-62427: All Xen versions from 4.0 onwards are vulnerable. Earlier versions use a different locking operation but may also be vulnerable.
- CVE-2026-62428: All Xen versions from 4.2 onwards are vulnerable. Xen 4.1 and earlier are not vulnerable. Xen 4.13 and later built without grant table support (
CONFIG_GRANT_TABLEturned off) are not vulnerable. - CVE-2026-62429: All Xen versions from 4.5 onwards are vulnerable. Xen 4.4 and earlier are not vulnerable. Only entities controlling guests—on x86, HVM guests—can leverage the vulnerability. These are device models running in either a stub domain or de-privileged in Dom0. Only guests with vNUMA enabled allow their controlling entities to leverage the vulnerability.
- CVE-2026-62430: All Xen versions from 3.2 onwards are vulnerable. Xen 3.1 and earlier are not vulnerable.
- CVE-2026-62431: All Xen versions from 4.13 onwards are vulnerable. Xen 4.12 and earlier are not vulnerable. Only HVM guests with Viridian STIMERs enabled can trigger the vulnerability.
- CVE-2026-62432: All Xen versions from 4.5 onwards are vulnerable. Xen 4.4 and earlier are not vulnerable.
- CVE-2026-62433: All Xen versions from 4.10 onwards are vulnerable. Xen 4.9 and earlier are not vulnerable. Only entities controlling HVM guests can leverage the vulnerability. These are device models running in either a stub domain or de-privileged in Dom0.
- CVE-2026-62434: All Xen versions from 3.4 onwards are vulnerable. Xen 3.3 and earlier are not vulnerable. Only x86 systems are vulnerable. Only x86 HVM and PVH guests started in populate-on-demand mode are believed to be able to leverage the vulnerability. This mode is activated when the guest's
xlconfiguration specifies amaxmemvalue larger than itsmemoryvalue. - CVE-2026-62435: All Xen versions from 4.0 onwards are vulnerable. Xen 3.4 and earlier are not vulnerable. Only multi-vCPU x86 guests permitted to use grant table version 2 interfaces can leverage the vulnerability. Grant table version 2 is explicitly unsupported on Arm. Xen 4.13 and later built without grant table support (
CONFIG_GRANT_TABLEturned off) are not vulnerable. - CVE-2026-62436: All Xen versions from 4.0 onwards are vulnerable. Xen 3.4 and earlier are not vulnerable. Only multi-vCPU x86 guests permitted to use grant table version 2 interfaces can leverage the vulnerability. Grant table version 2 is explicitly unsupported on Arm. Xen 4.13 and later built without grant table support (
CONFIG_GRANT_TABLEturned off) are not vulnerable.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Apply fixes issued by the vendor:
- https://xenbits.xen.org/xsa/advisory-495.html
- https://xenbits.xen.org/xsa/advisory-496.html
- https://xenbits.xen.org/xsa/advisory-497.html
- https://xenbits.xen.org/xsa/advisory-499.html
- https://xenbits.xen.org/xsa/advisory-500.html
- https://xenbits.xen.org/xsa/advisory-501.html
- https://xenbits.xen.org/xsa/advisory-502.html
- https://xenbits.xen.org/xsa/advisory-503.html
- https://xenbits.xen.org/xsa/advisory-504.html
- https://xenbits.xen.org/xsa/advisory-505.html
- https://xenbits.xen.org/xsa/advisory-506.html
- https://xenbits.xen.org/xsa/advisory-507.html
Vulnerability Identifier
- CVE-2026-42492
- CVE-2026-42493
- CVE-2026-42494
- CVE-2026-42495
- CVE-2026-62423
- CVE-2026-62424
- CVE-2026-62425
- CVE-2026-62426
- CVE-2026-62427
- CVE-2026-62428
- CVE-2026-62429
- CVE-2026-62430
- CVE-2026-62431
- CVE-2026-62432
- CVE-2026-62433
- CVE-2026-62434
- CVE-2026-62435
- CVE-2026-62436
Source
Related Link
- https://xenbits.xen.org/xsa/advisory-495.html
- https://xenbits.xen.org/xsa/advisory-496.html
- https://xenbits.xen.org/xsa/advisory-497.html
- https://xenbits.xen.org/xsa/advisory-499.html
- https://xenbits.xen.org/xsa/advisory-500.html
- https://xenbits.xen.org/xsa/advisory-501.html
- https://xenbits.xen.org/xsa/advisory-502.html
- https://xenbits.xen.org/xsa/advisory-503.html
- https://xenbits.xen.org/xsa/advisory-504.html
- https://xenbits.xen.org/xsa/advisory-505.html
- https://xenbits.xen.org/xsa/advisory-506.html
- https://xenbits.xen.org/xsa/advisory-507.html
沒有留言:
發佈留言