CVE-2026-42493 (GCVE-0-2026-42493)
Vulnerability from cvelistv5
Published
2026-07-28 12:31
Modified
2026-07-28 16:33
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Addressing certain issues, in particular related to operations which may
take excessively long and therefore would need preemption, has turned out
overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly
available, the decision was to deprecate the functionality, while still
retaining it for people to use at their own (security) risk. Memory-wise
small enough guests may still be okay to run.
References
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-07-28T16:33:23.792Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://xenbits.xen.org/xsa/advisory-495.html"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/07/28/12"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-42493",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-28T15:58:19.075241Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-28T15:58:45.484Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "Xen",
"vendor": "Xen",
"versions": [
{
"status": "unknown",
"version": "consult Xen advisory XSA-495"
}
]
}
],
"configurations": [
{
"lang": "en",
"value": "All x86 systems with builds of Xen having SHADOW_PAGING=y are affected.\nNote that prior to Xen 4.7 this control didn\u0027t exist, and all builds of\nXen would be affected. (Strictly speaking Xen 4.6 had a different, harder\nto use mechanism to disable shadow paging support: One could pass\n\"shadow-paging=n\" on the make command line.)"
}
],
"datePublic": "2026-07-28T12:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Addressing certain issues, in particular related to operations which may\ntake excessively long and therefore would need preemption, has turned out\noverly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly\navailable, the decision was to deprecate the functionality, while still\nretaining it for people to use at their own (security) risk. Memory-wise\nsmall enough guests may still be okay to run."
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "An unprivileged guest may be able to cause Denial of Service (DoS)\naffecting the entire host."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-28T12:31:11.950Z",
"orgId": "23aa2041-22e1-471f-9209-9b7396fa234f",
"shortName": "XEN"
},
"references": [
{
"url": "https://xenbits.xenproject.org/xsa/advisory-495.html"
}
],
"title": "x86 shadow paging is deprecated",
"workarounds": [
{
"lang": "en",
"value": "Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this\nvulnerability.\n\nThere\u0027s no mitigation available for PV guests. This is because shadow\nmode, if support is enabled in the hypervisor, could be engaged at any\ntime. Note that without shadow mode built into Xen, guests not properly\ndealing with L1TF will simply be crashed instead."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "23aa2041-22e1-471f-9209-9b7396fa234f",
"assignerShortName": "XEN",
"cveId": "CVE-2026-42493",
"datePublished": "2026-07-28T12:31:11.950Z",
"dateReserved": "2026-04-27T14:20:24.139Z",
"dateUpdated": "2026-07-28T16:33:23.792Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"http://xenbits.xen.org/xsa/advisory-495.html\"}, {\"url\": \"http://www.openwall.com/lists/oss-security/2026/07/28/12\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2026-07-28T16:33:23.792Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.5, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-42493\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"yes\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-28T15:58:19.075241Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-400\", \"description\": \"CWE-400 Uncontrolled Resource Consumption\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-28T15:57:59.081Z\"}}], \"cna\": {\"title\": \"x86 shadow paging is deprecated\", \"impacts\": [{\"descriptions\": [{\"lang\": \"en\", \"value\": \"An unprivileged guest may be able to cause Denial of Service (DoS)\\naffecting the entire host.\"}]}], \"affected\": [{\"vendor\": \"Xen\", \"product\": \"Xen\", \"versions\": [{\"status\": \"unknown\", \"version\": \"consult Xen advisory XSA-495\"}], \"defaultStatus\": \"unknown\"}], \"datePublic\": \"2026-07-28T12:00:00.000Z\", \"references\": [{\"url\": \"https://xenbits.xenproject.org/xsa/advisory-495.html\"}], \"workarounds\": [{\"lang\": \"en\", \"value\": \"Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this\\nvulnerability.\\n\\nThere\u0027s no mitigation available for PV guests. This is because shadow\\nmode, if support is enabled in the hypervisor, could be engaged at any\\ntime. Note that without shadow mode built into Xen, guests not properly\\ndealing with L1TF will simply be crashed instead.\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"Addressing certain issues, in particular related to operations which may\\ntake excessively long and therefore would need preemption, has turned out\\noverly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly\\navailable, the decision was to deprecate the functionality, while still\\nretaining it for people to use at their own (security) risk. Memory-wise\\nsmall enough guests may still be okay to run.\"}], \"configurations\": [{\"lang\": \"en\", \"value\": \"All x86 systems with builds of Xen having SHADOW_PAGING=y are affected.\\nNote that prior to Xen 4.7 this control didn\u0027t exist, and all builds of\\nXen would be affected. (Strictly speaking Xen 4.6 had a different, harder\\nto use mechanism to disable shadow paging support: One could pass\\n\\\"shadow-paging=n\\\" on the make command line.)\"}], \"providerMetadata\": {\"orgId\": \"23aa2041-22e1-471f-9209-9b7396fa234f\", \"shortName\": \"XEN\", \"dateUpdated\": \"2026-07-28T12:31:11.950Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-42493\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-28T16:33:23.792Z\", \"dateReserved\": \"2026-04-27T14:20:24.139Z\", \"assignerOrgId\": \"23aa2041-22e1-471f-9209-9b7396fa234f\", \"datePublished\": \"2026-07-28T12:31:11.950Z\", \"assignerShortName\": \"XEN\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…