Bug 2508137 - CVE-2026-62427 xen: Xen: Platform operation lock bypass leading to unauthorized access or denial of service [fedora-all]
Summary: CVE-2026-62427 xen: Xen: Platform operation lock bypass leading to unauthoriz...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: xen
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Michael Young
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["2c2aaf3b-a9f6-462c-bd64-f...
Depends On:
Blocks: CVE-2026-62427
TreeView+ depends on / blocked
 
Reported: 2026-07-28 17:51 UTC by Ganesh
Modified: 2026-07-28 17:51 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-07-28 17:51:09 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

To manage the system, sysctl and platform operations are used by the
control domain or a possible Xenstore domain.  Some of these operations
may not be executed in parallel, so a system-wide lock each is used.
The way those locks are acquired is, however, not providing any fairness.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking.

The sysctl issue is CVE-2026-62426.

The platform-op issue is CVE-2026-62427.


Note You need to log in before you can comment on or make changes to this bug.