CVE-2026-62433: Xen

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation without any checking being done. As a result, certain operations might access stack rubble as structures are possibly uninitialized.

Affected products

Published 2026-07-28. Last modified 2026-07-28.