CVE-2026-62432: Xen
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
Affected products
- Xen Xen
Published 2026-07-28. Last modified 2026-07-28.