Reachable assertion in Xen - CVE-2026-23557
Published: April 28, 2026
Xen
Xen Project
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an assertion failure in xenstored when processing an XS_RESET_WATCHES command within a transaction. A remote attacker can issue a crafted XS_RESET_WATCHES command within a transaction to cause a denial of service.
Only systems using the C variant of xenstored or xenstore-stubdom built without NDEBUG are vulnerable.