CVE-2026-62429 Details
Description
Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest.
A vulnerability exists in Xen hypervisor versions 4.5 and later, allowing access to a guest's vNUMA configuration data even after the domain destruction process has begun. This issue arises because the removal of vNUMA data is not properly synchronized with its access by the device model managing the guest. As a result, there is a potential for information leaks and denial-of-service effects on the host. Furthermore, in some cases, a device model stub domain or a de-privileged device model in the control domain could escalate privileges to that of the host.
Users can apply the appropriate patch available in the Xen Security Advisory XSA-502 to address this vulnerability. Patches for Xen 4.18.x to 4.21.x and for Xen 4.22.0 are available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 28, 2026CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/28/18 | CVE | |
| http://xenbits.xen.org/xsa/advisory-502.html | CVE | |
| https://xenbits.xenproject.org/xsa/advisory-502.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xen | >= 4.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 28, 2026 | CVE Modified | CVE |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | CVE Modified | CVE |
| Jul 28, 2026 | New CVE Received | [email protected] |
Volerion