CVE-2026-42493
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. Memory-wise small enough guests may still be okay to run.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Xen | Xen | consult Xen advisory XSA-495 | unknown |
Weaknesses
Workarounds
Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this vulnerability.
There's no mitigation available for PV guests. This is because shadow mode, if support is enabled in the hypervisor, could be engaged at any time. Note that without shadow mode built into Xen, guests not properly dealing with L1TF will simply be crashed instead.
ADP Enrichment
CVE Program Container
Additional References
- http://xenbits.xen.org/xsa/advisory-495.html
- http://www.openwall.com/lists/oss-security/2026/07/28/12
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.