๐Ÿ” CVE Alert

CVE-2026-62426

UNKNOWN 0.0

sysctl and platform-op locks open to abuse

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. The sysctl issue is CVE-2026-62426. The platform-op issue is CVE-2026-62427.

Vendor xen
Product xen
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for xen xen

Be the first to know when new unknown vulnerabilities affecting xen xen are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Xen / Xen
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
xenbits.xenproject.org: https://xenbits.xenproject.org/xsa/advisory-499.html

Credits

This issue was discovered by Jan Beulich of SUSE.