CVE-2026-62429: Xen

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest.

Affected products

Published 2026-07-28. Last modified 2026-07-28.