Executive brief
A vulnerability exists in the Xen virtualization platform's tool for reading disk images. A malicious guest operating system could provide a specially crafted disk image that causes the host system to crash or allows the guest to take full control of the physical host server. This could lead to a complete compromise of all data and services running on that hardware.
Technical details
The vulnerability is a buffer overrun located in the iso9660 driver of libfsimage. The root cause is the Rock Ridge extension loop assuming a valid inner record length derived directly from attacker-controlled on-disk fields without proper validation. An attacker with control over a guest VM can exploit this when the host uses pygrub to boot the guest's disk image. Successful exploitation allows for privilege escalation from the guest domain to the domain construction tools, typically resulting in host-level control. A patch is available from the Xen Project (XSA-497).
Affected products
- Xen Project Xen 3.2 and later
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched