CVE-2026-62427
sysctl and platform-op locks open to abuse
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. The sysctl issue is CVE-2026-62426. The platform-op issue is CVE-2026-62427.
| Vendor | xen |
| Product | xen |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for xen xen
Be the first to know when new unknown vulnerabilities affecting xen xen are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Xen / Xen
All versions affected References
Credits
This issue was discovered by Jan Beulich of SUSE.