Bug 2498541 (CVE-2026-23560)
| Summary: | CVE-2026-23560 xen: Xen: VM-admin can hide virtual machines from management and operations | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Xen. A virtual machine administrator (vm-admin) can exploit this by setting the VM.other-config:is_system_domain parameter, which allows them to mark a virtual machine as a system domain. This can lead to the virtual machine being ignored and remaining operational during critical host or pool operations, and potentially being hidden from management tools, impacting system visibility and control.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2499663 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-09 16:01:24 UTC
|