CVE-2026-23558Disclosure(xen / xen)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table version change from v2 to v1 in parallel with mapping the status page(s) via XENMEM_add_to_physmap. Some of the status pages may then be freed while mappings of them would still be inserted into the guest's secondary (P2M) page tables.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xen

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
xen

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-29: 1Mentions · 2026-05-19: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-19: 104-2905-19
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-05-191
General1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Xen 485 v2 (CVE-2026-31786): Linux kernel out of bounds read via Xen-related sysfs file https://www.openwall.com/lists/oss-security/2026/04/28/12 486 v2 (CVE-2026-23558): grant table v2 race in status page mapping https://www.openwall.com/lists/oss-security/2026/04/28/13 2/3

    Post summary

    Two Xen kernel vulnerabilities (CVE‑2026‑31786 and CVE‑2026‑23558) are disclosed with brief technical descriptions and links to Openwall mailing list entries; no exploitation, patches, or PoCs are mentioned.

    11030334
    4.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-23558 The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table version change fr… https://www.cve.org/CVERecord?id=CVE-2026-23558

    Post summary

    The post notes that after XSA‑379 and XSA‑387 fixes, CVE‑2026‑23558 still has a race condition related to grant table version changes, but it provides no evidence of an active exploit, PoC, or patch.

    00000151
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSxenxen---

Explore more