Inadequate Grant Table Lock Mechanism in Xen Project Software
CVE-2026-62435

Currently unrated

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-62435?

This vulnerability arises from an improper handling mechanism in the Grant Table of Xen Hypervisor software. Specifically, when transitioning between Grant Table versions, the system mistakenly assumes that certain properties remain unchanged during the period when the lock is dropped and later reacquired. This can lead to inconsistencies in the grant references and erroneous operation of the hypervisor. As a result, users and administrators may experience unexpected behavior, which highlights the crucial need for robust locking algorithms in virtualization technologies.

Affected Version(s)

Xen consult Xen advisory XSA-501

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Mark Esler.
.