VYPR
High severity7.9NVD Advisory· Published Jun 18, 2026· Updated Jun 22, 2026

CVE-2026-42487

CVE-2026-42487

Description

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.

Affected products

9

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.