Database/Kernel, userspace & hypervisor

Xen (x86 HVM): x86 HVM I/O port list traversal flaw
UnscoredCVE-2026-42487Kernel, userspace & hypervisorXSA-491curated
Impact
x86 HVM I/O port list traversal flaw
Who can reach it
Tenant VM guest (HVM)
What to do
Hypervisor patch + reboot/evacuation
References
Related entries
- OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window framesCVE-2026-42772 · OpenSSL QUIC stream reassembly (out-of-order frame buffer list)Unscored
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryCVE-2026-49430 · FreeBSD ZFS ZFS_IOC_RECV_NEW ioctl (heal receive path)Unscored
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetCVE-2026-49431 · FreeBSD ZFS ZFS_IOC_SET_PROP ioctl (zfs-set privilege check)Unscored
- OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per streamCVE-2026-54873 · OpenSSL QUIC stack (zero-copy packet buffer retention per stream)Unscored
- Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor stateCVE-2026-62428 · Xen (grant tables)Unscored
- Xen (grant tables): Grant-table version change racing with other operationsCVE-2026-62435 · Xen (grant tables)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.