Reachable assertion in Xen - CVE-2026-23555
Published: March 18, 2026
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to improper input validation in xenstored when processing Xenstore commands with the node path of "/local/domain/". A local user can send a specially crafted request containing this illegal path to crash xenstored or force it into an infinite loop, resulting in a denial of service for Xenstore operations.
Exploitation does not require guest privileges beyond the ability to issue Xenstore commands. The vulnerability affects systems using the C variant of xenstored; systems using oxenstored or xenstore-stubdom are not affected.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen-libs
xen-tools-xendomains-wait-disk
xen-libs-32bit-debuginfo
xen-libs-32bit
xen-tools
xen-libs-debuginfo
xen-tools-domU-debuginfo
xen-debugsource
xen-tools-debuginfo
xen-tools-domU
xen-devel
xen-doc-html
xen
How to mitigate CVE-2026-23555
xen-tools-xendomains-wait-disk - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-libs-32bit-debuginfo - update to 4.18.5_12-150600.3.40.1
xen-libs-32bit - update to 4.18.5_12-150600.3.40.1
xen-tools - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-libs-debuginfo - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-domU-debuginfo - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-debugsource - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-debuginfo - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-domU - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-devel - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-doc-html - update to 4.18.5_12-150600.3.40.1
xen - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen - addressed in versions 4.19.5-1.fc42, 4.20.2-4.fc43, 4.21.0-5.fc44, 4.21.1-1.fc44