CVE Explorer
CVE-2026-42492
Xenstore, to have an up-to-date picture of the entire system, wants to
know of domains appearing and disappearing. To make this more robust, a
new XEN_DOMCTL_get_domain_state was introduced. The management of the
bitmap underlying that operation is tied into the binding of the
VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear
down the bitmap even in cases when it wasn't set up. Unprivileged domains
can trigger that error path.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-496"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6e94d73ee2d0371882b033682b69efc3e3e10571316af2225f794bc27c4bca83 · sha256:8be40f3841d788cd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6e94d73ee2d0371882b033682b69efc3e3e10571316af2225f794bc27c4bca83 · sha256:8be40f3841d788cd… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-459","description":"CWE-459 Incomplete Cleanup","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6e94d73ee2d0371882b033682b69efc3e3e10571316af2225f794bc27c4bca83 · sha256:8be40f3841d788cd… · /containers/adp/1/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/07/28/13"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6e94d73ee2d0371882b033682b69efc3e3e10571316af2225f794bc27c4bca83 · sha256:8be40f3841d788cd… · /containers/adp/0/references/1
{"url":"http://xenbits.xen.org/xsa/advisory-496.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6e94d73ee2d0371882b033682b69efc3e3e10571316af2225f794bc27c4bca83 · sha256:8be40f3841d788cd… · /containers/adp/0/references/0
{"url":"https://xenbits.xenproject.org/xsa/advisory-496.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6e94d73ee2d0371882b033682b69efc3e3e10571316af2225f794bc27c4bca83 · sha256:8be40f3841d788cd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.