Back to CVE List

CVE-2026-62426

Vulnerability Description

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

To manage the system, sysctl and platform operations are used by the
control domain or a possible Xenstore domain. Some of these operations
may not be executed in parallel, so a system-wide lock each is used.
The way those locks are acquired is, however, not providing any fairness.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking.

The sysctl issue is CVE-2026-62426.

The platform-op issue is CVE-2026-62427.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Xen
Product
Xen

External References

Discussion (0)

Add Comment

No comments yet. Be the first!