Improper Initialization in Xen - CVE-2026-42492
Published: July 29, 2026
Xen
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the VIRQ_DOM_EXC virtual IRQ binding logic when binding event channels. A local user can trigger an error path from an unprivileged domain to cause a denial of service.
A hypervisor crash with host-wide impact is also possible, although unlikely.