#VU124114 Reachable assertion in Xen - CVE-2026-23555
Published: March 18, 2026
Xen
Xen Project
Description
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to improper input validation in xenstored when processing Xenstore commands with the node path of "/local/domain/". A local user can send a specially crafted request containing this illegal path to crash xenstored or force it into an infinite loop, resulting in a denial of service for Xenstore operations.
Exploitation does not require guest privileges beyond the ability to issue Xenstore commands. The vulnerability affects systems using the C variant of xenstored; systems using oxenstored or xenstore-stubdom are not affected.