Improper privilege management in Xen - #VU140013

 

Improper privilege management in Xen - #VU140013

Published: July 29, 2026


Vulnerability identifier: #VU140013
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper isolation in pygrub when processing guest-controlled boot and file system data. A remote user can supply a crafted guest boot environment to escalate privileges.

Successful exploitation can give control equivalent to the domain construction tools, typically resulting in control of the host.


Remediation

Install security update from vendor's website.

Sources