PT-2026-65468 · Xen+5 · Xen

·

CVE-2026-62426

·

Published

2026-07-28

·

Updated

2026-08-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
This update for xen fixes the following issues
  • CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
  • CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530).
  • CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531).
  • CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
  • CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534).
  • CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
  • CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
  • CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
  • CVE-2026-62433: correct buffer checks for DM OP hypercalls (bsc#1271538).
  • CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
  • pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62426
OPENSUSE-SU-2026:11441-1
SUSE-SU-2026:3409-1
SUSE-SU-2026:3423-1
SUSE-SU-2026:3451-1
SUSE-SU-2026:3462-1

Affected Products

Xen