Race condition in Xen - CVE-2026-62429

 

Race condition in Xen - CVE-2026-62429

Published: July 29, 2026


Vulnerability identifier: #VU140017
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-62429
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a local user to cause a denial of service, disclose sensitive information, or escalate privileges.

The vulnerability exists due to a race condition in the vNUMA configuration cleanup logic when accessing vNUMA configuration data during domain destruction. A local user can trigger concurrent access to stale configuration data to cause a denial of service, disclose sensitive information, or escalate privileges.

Only entities controlling HVM guests can leverage the issue, and only when vNUMA is enabled for the guest.


How to mitigate CVE-2026-62429

Install security update from vendor's website.

Sources