Junglewise Threat Intelligence

CVE-2026-42494: Xen libfsimage buffer overruns in iso9660 handling

CVE-2026-42494 · Severity: info · CVSS 0 · Published 2026-07-28

Technologies: Xen Project Xen. Vendors: Xen Project.

Executive brief

A vulnerability in the Xen virtualization platform's bootloader utility, pygrub, could allow a malicious guest operating system to take control of the entire host server. The issue exists in how the system processes ISO disk images, where specially crafted files can trigger memory errors. This could lead to a total compromise of the host's security and any other virtual machines running on it.

Technical details

Multiple buffer overflow vulnerabilities exist in the libfsimage iso9660 driver used by pygrub. The vulnerabilities (CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, and CVE-2026-62425) stem from the driver deriving record lengths, offsets, and entry sizes directly from attacker-controlled on-disk fields without proper validation during directory and Rock Ridge/SUSP walks. An attacker with the ability to provide a malicious ISO image to pygrub (typically a guest VM administrator) can trigger these overflows to execute arbitrary code with the privileges of the domain construction tools, potentially leading to a full host escape. Patches are available via Xen Security Advisory XSA-497.

Affected products

  • Xen Project Xen 3.2 and later

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats