Junglewise Threat Intelligence

CVE-2026-62435: Xen grant table race condition in version switching

CVE-2026-62435 · Severity: info · CVSS 8.8 · Published 2026-07-28

Technologies: Xen Project Xen. Vendors: Xen Project.

Executive brief

A vulnerability exists in the Xen hypervisor, which is software used to run multiple virtual machines on a single physical server. A malicious user controlling a virtual machine could exploit a flaw in how the system manages memory sharing (grant tables) to break out of their isolated environment. This could allow them to gain full control over the host server, access data from other customers, or cause a total system crash.

Technical details

A race condition exists in the Xen grant table version switching mechanism (specifically v1 to v2 transitions). The vulnerability occurs because the code drops and re-acquires the grant table lock, incorrectly assuming that table properties remain static during the unlocked window. An unprivileged multi-vCPU x86 guest can exploit this timing window to manipulate grant references. This can lead to host privilege escalation, information disclosure, or a denial of service. The issue affects all Xen versions from 4.0 onwards, provided grant table v2 is enabled and the guest is running on x86 architecture.

Affected products

  • Xen Project Xen 4.0 onwards

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats