Database/Kernel, userspace & hypervisor

Xen (x86 PV): Insufficient care with non-coherent mappings - PV guest to host compromise
CVSS 6.7CVE-2022-26363Kernel, userspace & hypervisorXSA-402curated
Impact
Insufficient care with non-coherent mappings - PV guest to host compromise
Who can reach it
Tenant VM guest (PV)
What to do
Hypervisor patch; livepatchable via Xen livepatch, otherwise host reboot + guest evacuation
References
Related entries
- Xen (x86 PV): Race condition in typeref acquisition - PV guest escalates to host privilegeCVE-2022-26362 · Xen (x86 PV)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.CVE-2023-53446 · Linux kernel (drivers/pci/pcie)Medium
- Intel oneAPI Math Kernel Library (oneMKL): An uncontrolled library search path: the component loads a shared libraryCVE-2024-21766 · Intel oneAPI Math Kernel Library (oneMKL)Medium
- Linux kernel - NVMe-oF target configfs, drivers/nvme/target/configfs.c: Nvmet_root_discovery_nqn_store() treated theCVE-2024-53681 · Linux kernel - NVMe-oF target configfs, drivers/nvme/target/configfs.cMedium
- polkit: out-of-bounds write parsing deeply nested XML policy filesCVE-2025-7519 · polkit (XML policy parser, nested-element depth)Medium
- systemd-homed: local homed-managed user can gain membership in arbitrary system groupsCVE-2026-16742 · systemd-homed (homed-managed user record group membership)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.