Type Confusion in Xen - CVE-2026-62428

 

Type Confusion in Xen - CVE-2026-62428

Published: July 29, 2026


Vulnerability identifier: #VU140018
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-62428
CWE-ID: CWE-843
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to type confusion in grant-copy operations when processing grant-copy requests involving a pinned grant. A local user can trigger concurrent grant operations to escalate privileges.

Information disclosure and denial of service are also possible. Systems built without grant table support are not vulnerable.


How to mitigate CVE-2026-62428

Install security update from vendor's website.

Sources