Количество 6
Количество 6
CVE-2026-62427
([This CNA information record relates to multiple CVEs; the text explai ...)
CVE-2026-62427
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. The sysctl issue is CVE-2026-62426. The platform-op issue is CVE-2026-62427.
CVE-2026-62427
[This CNA information record relates to multiple CVEs; the text explai ...
GHSA-92vf-cq3f-7mp6
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. The sysctl issue is CVE-2026-62426. The platform-op issue is CVE-2026-62427.
SUSE-SU-2026:3423-1
Security update for xen
SUSE-SU-2026:3409-1
Security update for xen
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62427 ([This CNA information record relates to multiple CVEs; the text explai ...) | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
CVE-2026-62427 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. The sysctl issue is CVE-2026-62426. The platform-op issue is CVE-2026-62427. | CVSS3: 8.8 | 0% Низкий | 9 дней назад | |
CVE-2026-62427 [This CNA information record relates to multiple CVEs; the text explai ... | CVSS3: 8.8 | 0% Низкий | 9 дней назад | |
GHSA-92vf-cq3f-7mp6 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. The sysctl issue is CVE-2026-62426. The platform-op issue is CVE-2026-62427. | CVSS3: 8.8 | 0% Низкий | 9 дней назад | |
SUSE-SU-2026:3423-1 Security update for xen | 7 дней назад | |||
SUSE-SU-2026:3409-1 Security update for xen | 8 дней назад |
Уязвимостей на страницу