Improper locking in Xen - CVE-2026-42489
Published: June 9, 2026
Xen
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock management in domctl operations when acquiring a system-wide lock for operations that may not be executed in parallel. A local user can repeatedly invoke domctl operations to cause a denial of service.
The issue can allow a less privileged entity to stall an equally or more privileged entity, potentially affecting the entire host.