CVE-2026-62432: Xen

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.

Affected products

Published 2026-07-28. Last modified 2026-07-28.