Improper privilege management in Xen - #VU140013

 

Improper privilege management in Xen - #VU140013

Published: July 29, 2026


Vulnerability identifier: #VU140013
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper isolation in pygrub when processing guest-controlled boot and file system data. A remote user can supply a crafted guest boot environment to escalate privileges.

Successful exploitation can give control equivalent to the domain construction tools, typically resulting in control of the host.


Affected software

Xen

Remediation

Install security update from vendor's website.


External References

Related Security Bulletins