CVE Explorer
CVE-2026-23553
In the context switch logic Xen attempts to skip an IBPB in the case of
a vCPU returning to a CPU on which it was the previous vCPU to run.
While safe for Xen's isolation between vCPUs, this prevents the guest
kernel correctly isolating between tasks. Consider:
1) vCPU runs on CPU A, running task 1.
2) vCPU moves to CPU B, idle gets scheduled on A. Xen skips IBPB.
3) On CPU B, guest kernel switches from task 1 to 2, issuing IBPB.
4) vCPU moves back to CPU A. Xen skips IBPB again.
Now, t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-693","description":"CWE-693 Protection Mechanism Failure","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/1/problemTypes/1/descriptions/0
{"cweId":"CWE-665","description":"CWE-665 Improper Initialization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/1/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-479"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":2.9,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-693","description":"CWE-693 Protection Mechanism Failure","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/1/problemTypes/1/descriptions/0
{"cweId":"CWE-665","description":"CWE-665 Improper Initialization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/1/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/01/27/3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/0/references/0
{"url":"http://xenbits.xen.org/xsa/advisory-479.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/adp/0/references/1
{"url":"https://xenbits.xenproject.org/xsa/advisory-479.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:702445e9566793bc78f5374bedb92ee0c408bde4fb0917b8a80735520b02aadd · sha256:bb0c6ca9752dbce9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.