freenode

← digests

Xen advisories and kernel flaws dominate security updates

Security & Cryptography2026-07-29

Xen Project issued a cluster of security advisories fixing privilege-escalation and crash bugs across grant tables, memory management, and related subsystems. Separate reports disclosed a local root issue in the Linux Open vSwitch datapath and multiple server flaws in the Eclipse Milo OPC UA SDK.

Xen grant-table type confusion (XSA-500)

Xen published Security Advisory 500 version 2 under CVE-2026-62428, describing a type confusion in the grant-table grant-copy path. A malicious guest could potentially escalate privileges to the host. Administrators running affected Xen versions should apply the patches promptly.

Xen PoD memory reclamation fix (XSA-507)

Xen released Security Advisory 507 version 2 for CVE-2026-62434, which corrects improper reclamation of special pages in the populate-on-demand code. The bug has been present since Xen 3.4 on x86 HVM and PVH guests and can lead to memory corruption with possible privilege escalation. Hosts using PoD should update to the fixed releases.

Xen grant-table version-change races (XSA-501)

Xen issued Security Advisory 501 version 4 covering CVE-2026-62435 and CVE-2026-62436. The advisories address races between grant-table version changes and concurrent operations that may permit guest-to-host privilege escalation. Operators should install the corresponding Xen updates.

Xen vNUMA domain cleanup race (XSA-502)

Xen published Security Advisory 502 version 3 under CVE-2026-62429. A race during vNUMA domain cleanup can allow a device model to escalate privileges on the host. Systems that expose vNUMA configurations need the supplied fixes.

Linux OVS local root via OVSwrap

A public disclosure detailed CVE-2026-64531, a local root vulnerability in the Linux kernel Open vSwitch datapath known as OVSwrap. The issue was fixed in recent stable kernel releases after an embargo period. Kernel maintainers and distributions shipping OVS should ensure the patches are applied.

Xen event-channel FIFO race (XSA-505)

Xen released Security Advisory 505 version 2 for CVE-2026-62432. A race between EVTCHNOP_expand_array and reset operations can produce a NULL dereference that crashes the hypervisor. Affected deployments should apply the advisory patches to restore stability.

Xen libfsimage iso9660 buffer overruns (XSA-497)

Xen published Security Advisory 497 version 2 covering five CVEs (CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425). Buffer overruns in the libfsimage iso9660 handling code can enable a guest-to-host escape when pygrub is used. Systems relying on pygrub for boot need the corrected library.

Eclipse Milo OPC UA server flaws

A security disclosure reported multiple vulnerabilities in Eclipse Milo versions up to 1.1.4, including a password-recovery padding oracle, a pre-authentication denial-of-service, and four additional server flaws. The issues are addressed in version 1.1.5. Users of the OPC UA SDK should upgrade to eliminate the exposure.