CVE-2026-23555Disclosure(xen / xen)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced via a failing assert() statement in xenstored. In case xenstored is being built with NDEBUG #defined, an unprivileged guest trying to access the node path "/local/domain/" will result in it no longer being serviced by xenstored, other guests (including dom0) will still be serviced, but xenstored will use up all cpu time it can get.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xen

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-17); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
xen

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-17: 2Mentions · 2026-03-23: 2Technical Details · 2026-03-17: 2Technical Details · 2026-03-23: 103-1703-23
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets5 URLs
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Xen Security Advisory 480 v3 (CVE-2026-23554) - Use after free of paging structures in EPT https://www.openwall.com/lists/oss-security/2026/03/17/6 Xen Security Advisory 481 v2 (CVE-2026-23555) - Xenstored DoS by unprivileged domain https://www.openwall.com/lists/oss-security/2026/03/17/7

    Post summary

    The text announces two new Xen security advisories (CVE-2026-23554 & CVE-2026-23555) with brief technical descriptions but no PoC, exploit code, patch details, or evidence of active exploitation.

    01062938
    4.4K followersView on X
  • Autumn Good@autumn_good_35
    General

    Xenで2件の脆弱性。 ただ、それよりも気になるのは事前リリース済みで3/24まで公開禁止となっているXSA-482ですね🤔 CVE-2026-23555 Xenstored DoS by unprivileged domain CVE-2026-23554 Use after free of paging structures in EPT Xen Security Advisories https://xenbits.xen.org/xsa/

    Post summary

    The post merely lists two Xen CVEs and points to the Xen Security Advisories page, with no indication of PoC, exploit, active use, or patch information.

    120401.7K
    6.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23555 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23555 #CVE-2026-23555 #CVE   #CyberSecurity #InfoSec https://t.co/p6unWxXmIg

    Post summary

    The tweet merely announces the existence of CVE‑2026‑23555 with unspecified details, providing no proof‑of‑concept, exploit, patch, or technical information.

    0000030
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23555 Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenst… https://www.cve.org/CVERecord?id=CVE-2026-23555

    Post summary

    The text announces CVE-2026-23555, a crash vulnerability in xenstored triggered by an illegal Xenstore path '/local/domain/' accessed by a guest. No PoC, exploit, patch, or active exploitation is mentioned.

    0000055
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSxenxen--x86

Explore more