The adjustments made for XSA-379 as well as those subsequently becoming
XSA-387 still left a race window, when a HVM or PVH guest does a grant
table version change from v2 to v1 in parallel with mapping the status
page(s) via XENMEM_add_to_physmap. Some of the status pages may then be
freed while mappings of them would still be inserted into the guest's
secondary (P2M) page tables.
Metrics
Affected Vendors & Products
References
History
Tue, 19 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-362 | |
| Metrics |
cvssV3_1
|
Tue, 19 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xen
Xen xen |
|
| Vendors & Products |
Xen
Xen xen |
Tue, 19 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 19 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table version change from v2 to v1 in parallel with mapping the status page(s) via XENMEM_add_to_physmap. Some of the status pages may then be freed while mappings of them would still be inserted into the guest's secondary (P2M) page tables. | |
| Title | grant table v2 race in status page mapping | |
| References |
|
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2026-05-19T14:36:29.452Z
Reserved: 2026-01-14T13:07:36.961Z
Link: CVE-2026-23558
Updated: 2026-05-19T13:06:51.044Z
Status : Undergoing Analysis
Published: 2026-05-19T14:16:38.960
Modified: 2026-05-19T16:16:19.667
Link: CVE-2026-23558
No data.
OpenCVE Enrichment
Updated: 2026-05-19T17:30:10Z