Input validation error in Xen - CVE-2026-62433

 

Input validation error in Xen - CVE-2026-62433

Published: July 29, 2026


Vulnerability identifier: #VU140021
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-62433
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper input validation in the DM_OP handling code when processing DM_OP hypercalls. A local user can provide an insufficient number of buffers for certain operations to disclose sensitive information.

Only entities controlling HVM guests can leverage the vulnerability, such as device models running in a stub domain or de-privileged in Dom0.


How to mitigate CVE-2026-62433

Install security update from vendor's website.

Sources