CVE-2026-62429: vNUMA domain cleanup may race other operations
Published Jul 28, 2026
·Updated
Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest.
Affected Software
1 affected component
Xen Project Xen
Event History
Jul 28, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
Description
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-62429?
The severity of CVE-2026-62429 is medium, with a CVSS score of 6.5.
2
How do I fix CVE-2026-62429?
To fix CVE-2026-62429, ensure that you apply the latest patches or updates provided by Xen Project.
3
What type of vulnerability is CVE-2026-62429?
CVE-2026-62429 is classified as a race condition vulnerability.
4
What does CVE-2026-62429 affect?
CVE-2026-62429 affects the vNUMA domain cleanup process within the Xen Project virtualization software.
5
What happens if CVE-2026-62429 is exploited?
If exploited, CVE-2026-62429 may allow unauthorized access to the vNUMA configuration data during domain destruction.