Junglewise Threat Intelligence

CVE-2026-62424: Xen libfsimage buffer overrun in Rock Ridge NM record processing

CVE-2026-62424 · Severity: info · CVSS 0 · Published 2026-07-28

Technologies: Xen Project Xen. Vendors: Xen Project.

Executive brief

A vulnerability exists in the Xen virtualization platform's file system image library (libfsimage). A malicious guest operating system can provide a specially crafted disk image that, when processed by the pygrub bootloader, allows the guest to escape its isolation and potentially take full control of the host server. This could lead to unauthorized access to other guests' data or a complete compromise of the virtualization infrastructure.

Technical details

A buffer overrun vulnerability exists in the iso9660 driver of libfsimage, specifically within the Rock Ridge NM (Name) record processing. The vulnerability stems from the driver deriving entry lengths directly from attacker-controlled on-disk fields without proper validation. An attacker with control over a guest's disk image can exploit this during the pygrub boot process to trigger a buffer overflow. This can lead to arbitrary code execution in the context of the domain construction tools, typically resulting in a full host escape. Mitigation is available by running pygrub in a de-privileged mode or using alternative bootloaders like pvgrub.

Affected products

  • Xen Project Xen 3.2 and later

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats