CVE-2026-42493 Details
Description
Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. Memory-wise small enough guests may still be okay to run.
A vulnerability exists in all x86 systems running Xen with shadow paging enabled, prior to version 4.7. This vulnerability allows an unprivileged guest to cause a denial-of-service condition affecting the entire host. The issue arises because operations in shadow paging can take excessively long, leading to preemption challenges. While alternatives are available, the decision was made to deprecate shadow paging, leaving it accessible for users who accept the associated security risks. Memory-efficient guests may still operate under this configuration.
To address this vulnerability, users can switch HVM and PVH guests to Hardware Assisted Paging (HAP) mode. However, there is no mitigation available for PV guests, as shadow mode could be reactivated at any time if supported by the hypervisor. For systems running Xen versions 4.17.x, 4.18.x, 4.20.x, or 4.21.x, the appropriate patch can be applied. Instructions for applying the patch are included in the advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 28, 2026CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/28/12 | CVE | |
| http://xenbits.xen.org/xsa/advisory-495.html | CVE | |
| https://xenbits.xenproject.org/xsa/advisory-495.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xen | < 4.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 28, 2026 | CVE Modified | CVE |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | CVE Modified | CVE |
| Jul 28, 2026 | New CVE Received | [email protected] |
Volerion