Out-of-bounds read in Xen - CVE-2026-31786
Published: April 28, 2026
Xen
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information, cause a denial of service, or escalate privileges.
The vulnerability exists due to an out-of-bounds read in the Xen-related sysfs buildid handler when reading the /sys/hypervisor/properties/buildid sysfs file. A local user can read the crafted sysfs output to disclose sensitive information, cause a denial of service, or escalate privileges.
In rare cases, the issue may also result in writing past the 4 kB sysfs buffer if no zero byte is found in adjacent data.