Description
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.
References (3)
Core 3
Core References
Various Sources
http://xenbits.xen.org/xsa/advisory-496.html
Scores
CVSS v3
7.5
EPSS
0.0048
EPSS Percentile
38.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-459
Status
published
Products (1)
Xen/Xen
consult Xen advisory XSA-496
Published
Jul 28, 2026
Tracked Since
Jul 28, 2026