Database/Kernel, userspace & hypervisor

Xen (x86 PV): Race condition in typeref acquisition - PV guest escalates to host privilege
CVSS 6.4CVE-2022-26362Kernel, userspace & hypervisorXSA-401curated
Impact
Race condition in typeref acquisition - PV guest escalates to host privilege
Who can reach it
Tenant VM guest (PV)
What to do
Hypervisor patch + host reboot with guest evacuation, or use Xen livepatch if the deployment supports it. Simplest structural fix: stop offering PV guests, run PVH/HVM only
References
Related entries
- Xen (x86 PV): Insufficient care with non-coherent mappings - PV guest to host compromiseCVE-2022-26363 · Xen (x86 PV)Medium
- QEMU (IDE/ATAPI): Improper IDE controller reset lets a guest overwrite the host MBR of an attached deviceCVE-2023-5088 · QEMU (IDE/ATAPI)Medium
- Intel DSA/IAA (idxd): Hardware erratum: direct access to Intel DSA/IAA accelerators by an untrusted application allowsCVE-2024-21823 · Intel DSA/IAA (idxd)Medium
- Linux kernel (drivers/pci): Pm_runtime_get_sync() does not wait for an already-running .runtime_idle() callback, so aCVE-2024-35809 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci/hotplug): Powering off a physical function that still has child virtual functions drops theCVE-2025-37946 · Linux kernel (drivers/pci/hotplug)Medium
- systemd: Privilege escalation via the systemctl `less` pager when sudo-granted systemctl is availableCVE-2023-26604 · systemdMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.