Event Channel Management Flaw in Xen Hypervisor by Xen Project
CVE-2026-62432

7.3HIGH

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-62432?

The Xen Hypervisor contains a vulnerability in its event channel management system, specifically within the EVTCHNOP_expand_array hypercall. This flaw permits a race condition with the EVTCHNOP_reset hypercall, which may lead to operations that attempt to dereference a NULL pointer due to improper locking mechanisms. If exploited, this vulnerability could disrupt normal operations of the hypervisor, potentially impacting the stability and security of virtual environments. Immediate remediation actions are recommended to mitigate associated risks.

Affected Version(s)

Xen consult Xen advisory XSA-505

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.