[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
To manage the system, sysctl and platform operations are used by the
control domain or a possible Xenstore domain. Some of these operations
may not be executed in parallel, so a system-wide lock each is used.
The way those locks are acquired is, however, not providing any fairness.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking.
The sysctl issue is CVE-2026-62426.
The platform-op issue is CVE-2026-62427.
References
| Link | Resource |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-499.html |
Configurations
No configuration.
History
28 Jul 2026, 16:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-284 CWE-305 |
28 Jul 2026, 13:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-28 13:19
Updated : 2026-07-28 16:19
NVD link : CVE-2026-62427
Mitre link : CVE-2026-62427
CVE.ORG link : CVE-2026-62427
JSON object : View
Products Affected
No product.
