High severity7.9NVD Advisory· Published Jun 18, 2026· Updated Jun 22, 2026
CVE-2026-42487
CVE-2026-42487
Description
HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.
Affected products
9- osv-coords9 versionspkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6
< 4.17.6_12-150500.3.73.1+ 8 more
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.20.3_06-150700.3.41.1
- (no CPE)range: < 4.20.3_06-150700.3.41.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.18.5_18-150600.3.50.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.18.5_18-150600.3.50.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.