CVE-2026-42492
Received Received - Intake

Xenstore Domain State Bitmap Error in Xen Hypervisor

Vulnerability report for CVE-2026-42492, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Xen Project

Description

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xen xen From 4.21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Xenstore, a component of the Xen hypervisor that tracks domain states. It involves an error in managing a bitmap tied to the VIRQ_DOM_EXC virtual IRQ. When an error occurs, the bitmap is torn down prematurely even if it wasn't set up correctly. Unprivileged domains can trigger this error path to disrupt Xenstore operations.

Detection Guidance

Detection of CVE-2026-42492 requires checking if your Xen version is 4.21 or later, as this is the affected range. No specific commands are provided in the advisory for detection, but monitoring for Xenstore disruptions or hypervisor crashes may indicate exploitation.

Impact Analysis

This vulnerability can lead to a Denial of Service (DoS) affecting the entire host system. In rare cases, it might also cause a hypervisor crash with similar consequences. Unprivileged domains can exploit this to disrupt Xenstore operations.

Compliance Impact

This vulnerability primarily causes Denial of Service (DoS) conditions or hypervisor crashes, which could disrupt system availability. While it does not directly impact data confidentiality or integrity, prolonged downtime may affect compliance with availability requirements in standards like GDPR or HIPAA.

Mitigation Strategies

Apply the patch provided in XSA-496 advisory immediately. If using Xen 4.21.x, deploy the patch as instructed. For stable branches, check for updates before applying. No other mitigations are known.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42492. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart