Bug 2508034 (CVE-2026-62427)
| Summary: | CVE-2026-62427 xen: Xen: Platform operation lock bypass leading to unauthorized access or denial of service | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Xen. The system-wide locks used for platform operations, which manage the system, do not ensure fair access. When Xen Security Modules (XSM) and Flask are active, these locks can be acquired before necessary permission checks are performed for certain operations. This could allow an attacker to bypass security restrictions, potentially leading to unauthorized access or a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2508137 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-28 14:03:05 UTC
|