Race condition in Xen - CVE-2026-42487
Published: June 9, 2026
Xen
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper synchronization in the I/O port mapping list traversal logic when handling guest I/O port accesses. A remote user can modify I/O port mappings during traversal to cause a denial of service.
Only x86 systems are vulnerable. Exploitation requires control of an HVM guest device model running in a stub domain or de-privileged in Dom0.