CVE Explorer
CVE-2026-62435
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
With the introduction of Grant Table v2 came the requirement to be able to
switch between versions. Switching from v1 to v2 reduces the number of
valid grant references, as a bigger shared entry structure is then needed
while the shared table doesn't change size. Switching from v2 back to v1
the status frames, which are separate in v2, go away.
Code holding, but in
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-501"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:58e263fca9164bccae2b5e708c6354b39615256150ac4fdddbf2372e89cd057c · sha256:5d2e849368f78757… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:58e263fca9164bccae2b5e708c6354b39615256150ac4fdddbf2372e89cd057c · sha256:5d2e849368f78757… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-362","description":"CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:58e263fca9164bccae2b5e708c6354b39615256150ac4fdddbf2372e89cd057c · sha256:5d2e849368f78757… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://xenbits.xenproject.org/xsa/advisory-501.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:58e263fca9164bccae2b5e708c6354b39615256150ac4fdddbf2372e89cd057c · sha256:5d2e849368f78757… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.