CVE-2026-62429
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Xen | Xen | consult Xen advisory XSA-502 | unknown |
Weaknesses
Workarounds
On x86, running only PV or PVH guests will avoid the vulnerability.
Not enabling vNUMA for HVM guests will also avoid the vulnerability.
ADP Enrichment
CVE Program Container
Additional References
- http://xenbits.xen.org/xsa/advisory-502.html
- http://www.openwall.com/lists/oss-security/2026/07/28/18
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.