https://seclists.org/oss-sec/2026/q2/246: Xen Security Advisory 484 v2 (CVE-2026-23557) - Xenstod DoS via XS_SET_WATCHES command
Published Apr 28, 2026
·Updated
Affected Software
3 affected components
Xen Project Xen>=4.2
Xen Project xenstored (C variant)>=4.2
Xen Project xenstore-stubdom (C variant)>=4.2
Frequently Asked Questions
1
What is the severity of CVE-2026-23557?
CVE-2026-23557 has been classified as a denial-of-service (DoS) vulnerability, which can lead to crashes in the xenstored service.
2
How do I fix CVE-2026-23557?
To mitigate CVE-2026-23557, update to the latest version of Xen Project Xen that contains the security patch addressing this vulnerability.
3
Who is affected by CVE-2026-23557?
All users of Xen Project Xen and related components, particularly those running xenstored, are potentially affected by CVE-2026-23557.
4
What does CVE-2026-23557 exploit?
CVE-2026-23557 exploits the XS_RESET_WATCHES command to create a denial-of-service condition in the xenstored service.
5
When was CVE-2026-23557 published?
CVE-2026-23557 was publicly released on April 28, 2026.