Medium severity5.3NVD Advisory· Published Jun 18, 2026· Updated Jun 22, 2026
CVE-2026-42489
CVE-2026-42489
Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489.
Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.
Affected products
9- osv-coords9 versionspkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6
< 4.17.6_12-150500.3.73.1+ 8 more
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.20.3_06-150700.3.41.1
- (no CPE)range: < 4.20.3_06-150700.3.41.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.18.5_18-150600.3.50.1
- (no CPE)range: < 4.17.6_12-150500.3.73.1
- (no CPE)range: < 4.18.5_18-150600.3.50.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.