Junglewise Threat Intelligence

CVE-2026-42495: Xen libfsimage integer underflow in iso9660 System Use area calculation

CVE-2026-42495 · Severity: info · CVSS 8.8 · Published 2026-07-28

Technologies: Xen Project Xen. Vendors: Xen Project.

Executive brief

A vulnerability exists in the Xen virtualization platform's tool for reading disk images. A malicious guest operating system can provide a specially crafted disk image that triggers a memory error when the host attempts to boot the guest. If successful, this allows the guest to break out of its isolation and gain full control over the host server, potentially compromising all other data and services on that physical machine.

Technical details

A vulnerability exists in the libfsimage iso9660 driver's handling of directory and Rock Ridge / SUSP walks. Specifically, CVE-2026-42495 involves an integer underflow during the calculation of the System Use area size because the driver derives lengths directly from attacker-controlled on-disk fields without validation. An attacker with the ability to provide a malicious ISO image to the pygrub bootloader can trigger a buffer overrun. This allows a guest VM to escalate privileges to the domain construction tools (typically Dom0), leading to a full host compromise. A patch is available from the Xen Project (XSA-497).

Affected products

  • Xen Project Xen 3.2 and later

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats