Database/Kernel, userspace & hypervisor

Xen (EPT): Use-after-free of EPT paging structures - HVM guest to host compromise
UnscoredCVE-2026-23554Kernel, userspace & hypervisorXSA-480curated
Impact
Use-after-free of EPT paging structures - HVM guest to host compromise
Who can reach it
Tenant VM guest (HVM)
What to do
Hypervisor patch + host reboot with guest evacuation. Highest-severity recent Xen item for a multi-tenant HVM fleet
References
Related entries
- OpenSSL: certificate with many relative-name CRL distribution points inflates heap on TLS handshakeCVE-2026-35189 · OpenSSL X.509 extension caching (CRL distribution points, nameRelativeToCRLIssuer)Unscored
- OpenSSL QUIC server: per-packet credit accounting breaks the RFC 9000 3x amplification limitCVE-2026-35191 · OpenSSL QUIC server (unvalidated address amplification credit accounting)Unscored
- Xen (x86 HVM): x86 HVM I/O port list traversal flawCVE-2026-42487 · Xen (x86 HVM)Unscored
- OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window framesCVE-2026-42772 · OpenSSL QUIC stream reassembly (out-of-order frame buffer list)Unscored
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryCVE-2026-49430 · FreeBSD ZFS ZFS_IOC_RECV_NEW ioctl (heal receive path)Unscored
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetCVE-2026-49431 · FreeBSD ZFS ZFS_IOC_SET_PROP ioctl (zfs-set privilege check)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.