Missing Release of Resource after Effective Lifetime in Xen - CVE-2026-23556
Published: April 28, 2026
Xen
Xen Project
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource management in oxenstored quota use counts when tearing down and reusing domain IDs. A remote user can deliberately hit its quota and reboot a domain to cause a denial of service.
Only systems configured to use oxenstored are vulnerable.