I/O Port Access Vulnerability in XEN Hypervisor by Xen Project
CVE-2026-42487
7.9HIGH
What is CVE-2026-42487?
A vulnerability exists in the XEN hypervisor, where handling of guest I/O port accesses lacks necessary synchronization during list traversal. This issue arises from the dynamic management of translations by the device model through XEN_DOMCTL_ioport_mapping, resulting in potential race conditions. If not addressed, this could lead to unexpected behavior or compromised guest isolation.
Affected Version(s)
Xen consult Xen advisory XSA-491