CVE-2026-42492: vIRQ event channel binding may break Xenstore
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XENDOMCTLgetdomainstate was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQDOMEXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42492?
CVE-2026-42492 has a severity rating of high, with a CVSS score of 7.5.
What does CVE-2026-42492 affect?
CVE-2026-42492 affects the Xen Project Xen software, specifically its Xenstore component.
How do I fix CVE-2026-42492?
Fixing CVE-2026-42492 typically involves applying the latest patches or updates provided by the Xen Project.
What are the potential impacts of CVE-2026-42492?
The potential impact of CVE-2026-42492 includes instability in domain management and possible degradation of system performance.
How does CVE-2026-42492 relate to Xenstore functionality?
CVE-2026-42492 may disrupt Xenstore's ability to accurately track the state of domains, affecting overall system robustness.