https://seclists.org/oss-sec/2026/q2/858: Xen Security Advisory 492 v3 (CVE-2026-42489,CVE-2026-42490) - domctl lock open to abuse
Published Jun 9, 2026
·Updated
Affected Software
1 affected component
Xen Project Xen>=3.3
Frequently Asked Questions
1
What is the severity of CVE-2026-42489?
CVE-2026-42489 has been classified as a medium severity vulnerability involving domctl lock abuse.
2
How do I fix CVE-2026-42489?
To mitigate CVE-2026-42489, users should update to the latest version of the Xen Project that includes the relevant patches.
3
What systems are affected by CVE-2026-42490?
CVE-2026-42490 affects all versions of the Xen Project that utilize domctl operations without proper access controls.
4
Is CVE-2026-42489 exploitable?
Yes, CVE-2026-42489 can potentially be exploited by unauthorized users to manipulate domctl operations.
5
What is the impact of CVE-2026-42490 on virtual machine management?
CVE-2026-42490 could lead to privilege escalation, allowing attackers to gain control over virtual machine management operations.