CVE Explorer
CVE-2026-23555
Any guest issuing a Xenstore command accessing a node using the
(illegal) node path "/local/domain/", will crash xenstored due to a
clobbered error indicator in xenstored when verifying the node path.
Note that the crash is forced via a failing assert() statement in
xenstored. In case xenstored is being built with NDEBUG #defined,
an unprivileged guest trying to access the node path "/local/domain/"
will result in it no longer being serviced by xenstored, other guests
(including dom0) will stil
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-481"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ef7b6b85e63d300e922ee22be4285fc69fd015df29fa9307aa247d39fbbe3776 · sha256:cc9bd49090cfa317… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ef7b6b85e63d300e922ee22be4285fc69fd015df29fa9307aa247d39fbbe3776 · sha256:cc9bd49090cfa317… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-617","description":"CWE-617 Reachable Assertion","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ef7b6b85e63d300e922ee22be4285fc69fd015df29fa9307aa247d39fbbe3776 · sha256:cc9bd49090cfa317… · /containers/adp/1/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/03/17/7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ef7b6b85e63d300e922ee22be4285fc69fd015df29fa9307aa247d39fbbe3776 · sha256:cc9bd49090cfa317… · /containers/adp/0/references/0
{"url":"http://xenbits.xen.org/xsa/advisory-481.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ef7b6b85e63d300e922ee22be4285fc69fd015df29fa9307aa247d39fbbe3776 · sha256:cc9bd49090cfa317… · /containers/adp/0/references/1
{"url":"https://xenbits.xenproject.org/xsa/advisory-481.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ef7b6b85e63d300e922ee22be4285fc69fd015df29fa9307aa247d39fbbe3776 · sha256:cc9bd49090cfa317… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.