CVE-2026-42488 Details
Description
Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between the loaded page-tables and the mapcache metadata which can lead to corruption of the mapcache.
A vulnerability in Xen Project's handling of shadow paging can lead to privilege escalation, denial-of-service (DoS) affecting the entire host, and information leaks. This issue arises because certain error paths in shadow paging switch the page tables without updating the reference to the currently running vCPU. As a result, there is a mismatch between the loaded page tables and the mapcache metadata, which can corrupt the mapcache. This vulnerability affects Xen versions 4.15 and onwards, specifically on x86 systems with 64-bit PV guests running in shadow mode, such as during guest migration or as a workaround for the L1TF vulnerability.
Users can apply the patch provided in the Xen Security Advisory XSA-494 to address this vulnerability. Patches are available for Xen 4.17.x, 4.18.x, 4.20.x - 4.19.x, and 4.21.x. For versions 4.15 and onwards, the vulnerability can be mitigated by running only HVM or PVH guests, or by using the PV shim for PV guests.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/09/14 | CVE | AdvisoryMailing ListRemedy |
| http://xenbits.xen.org/xsa/advisory-494.html | CVE | AdvisoryRemedyVendor |
| https://xenbits.xenproject.org/xsa/advisory-494.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xen | >= 4.15 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | CVE Modified | CVE |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion