Junglewise Threat Intelligence

CVE-2026-45890: Linux kernel guest-to-host DoS in xen-netback

CVE-2026-45890 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Xen networking component allows a guest virtual machine to crash the host server. By requesting an invalid network configuration, a malicious or malfunctioning guest can trigger a kernel panic on hosts configured to halt on warnings. This results in a denial of service, impacting all other virtual machines and services running on the same physical hardware.

Technical details

The xen-netback driver in the Linux kernel fails to validate that the 'multi-queue-num-queues' value provided by a Xen guest is greater than zero. When a guest writes '0' to this xenbus key, the connect() function passes this value to vzalloc(), which eventually triggers a WARN_ON_ONCE(!size) in __vmalloc_node_range(). On host systems configured with 'panic_on_warn=1', this warning results in a full system crash (kernel panic). The vulnerability is an input validation issue where only the upper bound of queues was checked. Patches have been released across multiple stable kernel branches to enforce the requirement that queue counts must be at least one.

Affected products

  • Linux Linux kernel All versions supporting multi-queue xen-netback prior to the fix

Timeline

  • 2026-02-12: disclosed: Initial patch submitted by Ziyi Guo
  • 2026-02-17: patched: Mainline kernel patch committed
  • 2026-05-27: advisory: CVE-2026-45890 published

References

Related threats