← Back

CVE-2026-42489

nvd nist
Published: Jun 18, 2026Modified: Jun 22, 2026Deferred

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Exploitability: 0.8 / Impact: 4.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.

References (1)

Timeline

No history available yet.