Improper privilege management in Xen - #VU140013
Published: July 29, 2026
Xen
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper isolation in pygrub when processing guest-controlled boot and file system data. A remote user can supply a crafted guest boot environment to escalate privileges.
Successful exploitation can give control equivalent to the domain construction tools, typically resulting in control of the host.