Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-23557

Опубликовано: 19 мая 2026
Источник: debian

Описание

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in this case. Note that the default is not to define NDEBUG for xenstored builds even in release builds of Xen.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.20.3+127-gc42374a105-1package

Примечания

  • https://xenbits.xen.org/xsa/advisory-484.html

  • Debian uses the ocaml-based xenstored

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in this case. Note that the default is not to define NDEBUG for xenstored builds even in release builds of Xen.

CVSS3: 6.5
nvd
3 месяца назад

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in this case. Note that the default is not to define NDEBUG for xenstored builds even in release builds of Xen.

CVSS3: 6.5
github
3 месяца назад

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in this case. Note that the default is not to define NDEBUG for xenstored builds even in release builds of Xen.

suse-cvrf
3 месяца назад

Security update for xen

suse-cvrf
4 месяца назад

Security update for xen