Vulnerability in Xen Project Hypervisor Affecting Long-Running Operations
CVE-2026-42493

7.5HIGH

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-42493?

The vulnerability exposes an issue in the Xen Project Hypervisor related to managing operations that may take excessively long. This situation leads to a costly overhead in handling preemption, which has prompted the vendor to deprecate certain functionalities while still allowing users to employ them at their own security risk. Users managing small memory guests may experience fewer issues; however, it's critical to evaluate the security implications before proceeding with deprecated configurations.

Affected Version(s)

Xen consult Xen advisory XSA-495

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.