Out-of-bounds read in Xen - CVE-2026-62430

 

Out-of-bounds read in Xen - CVE-2026-62430

Published: July 29, 2026


Vulnerability identifier: #VU140022
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-62430
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in vRTC emulation when handling indirect CMOS memory index accesses. A local user can change the cached index concurrently after it has been checked to disclose sensitive information.

The disclosed data is limited to Xen data and does not include data belonging to other guests.


How to mitigate CVE-2026-62430

Install security update from vendor's website.

Sources