CVE-2026-42494
The advisory mentions multiple vulnerable components as root cause of the security issues. Some of the vulnerable components are file system drivers, guest configuration files and specific functions. The most severe impact of the vulnerabilities is data leakage between guest VMs. Other possible results of exploitation includes denial of service and escalation of privileges. CVE-2026-62434, CVE-2026-62433, CVE-2026-62432 could lead to RAM from a different guest VM being claimed by the affected VM. The same flaws causing corruption of the Xen’s state are likely to lead to a crash of the host, affecting the availability of other VMs. Other vulnerabilities are limited to service disruptions, with privilege escalation and data leakage remaining theoretical.
EPSS 0.12% · 1.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen Project: Multiple versions (see source for details) |
Timeline
- Jul 28, 2026 CVE Published
- Jul 28, 2026 CVE Updated
- Jul 29, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 12, 2026 Distribution Patch
- Aug 12, 2026 Security Advisory
- Aug 13, 2026 Security Advisory