Reachable assertion in Xen - CVE-2026-23555

 

Reachable assertion in Xen - CVE-2026-23555

Published: March 18, 2026


Vulnerability identifier: #VU124114
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H]
CVE-ID: CVE-2026-23555
CWE-ID: CWE-617
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to improper input validation in xenstored when processing Xenstore commands with the node path of "/local/domain/". A local user can send a specially crafted request containing this illegal path to crash xenstored or force it into an infinite loop, resulting in a denial of service for Xenstore operations.

Exploitation does not require guest privileges beyond the ability to issue Xenstore commands. The vulnerability affects systems using the C variant of xenstored; systems using oxenstored or xenstore-stubdom are not affected.


Affected software

Xen
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen-libs
xen-tools-xendomains-wait-disk
xen-libs-32bit-debuginfo
xen-libs-32bit
xen-tools
xen-libs-debuginfo
xen-tools-domU-debuginfo
xen-debugsource
xen-tools-debuginfo
xen-tools-domU
xen-devel
xen-doc-html
xen

How to mitigate CVE-2026-23555

Install updates from vendor's website.

xen-libs - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-xendomains-wait-disk - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-libs-32bit-debuginfo - update to 4.18.5_12-150600.3.40.1
xen-libs-32bit - update to 4.18.5_12-150600.3.40.1
xen-tools - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-libs-debuginfo - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-domU-debuginfo - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-debugsource - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-debuginfo - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-tools-domU - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-devel - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen-doc-html - update to 4.18.5_12-150600.3.40.1
xen - addressed in versions 4.18.5_12-150600.3.40.1, 4.20.2_08-150700.3.28.1
xen - addressed in versions 4.19.5-1.fc42, 4.20.2-4.fc43, 4.21.0-5.fc44, 4.21.1-1.fc44

External References

Related Security Bulletins