CVE-2026-23556: Xen Oxenstored

Critical severity, CVSS 9.4. EPSS: 0.1% chance of exploitation in the next 30 days.

When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.

Affected products

  • Xen Oxenstored: any version

Published 2026-07-09. Last modified 2026-07-09.