[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
To create and manage guests, domctl operations are used by the control
domain, a possible Xenstore domain, or by a domain controlling a
particular guest. Some of these operations may not be executed in
parallel, so a system-wide lock is used. The way that lock is acquired
is, however, not providing any fairness. This is CVE-2026-42489.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking. This is
CVE-2026-42490.
References
| Link | Resource |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-492.html |
Configurations
No configuration.
History
18 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 14:17
Updated : 2026-06-22 18:38
NVD link : CVE-2026-42490
Mitre link : CVE-2026-42490
CVE.ORG link : CVE-2026-42490
JSON object : View
Products Affected
No product.
CWE
CWE-667
Improper Locking
