CVE-2026-42492
vIRQ event channel binding may break Xenstore
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.
| Vendor | xen |
| Product | xen |
| Published | Jul 28, 2026 |
| Last Updated | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for xen xen
Be the first to know when new unknown vulnerabilities affecting xen xen are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Xen / Xen
All versions affected References
Credits
This issue was discovered by Grygorii Strashko of EPAM.