Database/Kernel, userspace & hypervisor

Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor state
UnscoredCVE-2026-62428Kernel, userspace & hypervisorXSA-500curated
Impact
Type confusion in grant-copy - guest corrupts hypervisor state
Who can reach it
Tenant VM guest
What to do
Hypervisor patch + reboot/evacuation. Grant tables are on the hot path for every PV driver, so this is unavoidable exposure
References
Related entries
- Xen (grant tables): Grant-table version change racing with other operationsCVE-2026-62435 · Xen (grant tables)Unscored
- OpenSSL: attacker-controlled CMP sender DN reaches ERR_raise_data() as a format string, crashing the clientCVE-2026-63073 · OpenSSL CMP client (ossl_cmp_msg_check_update sender DN handling)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2026-63882 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel x86: no IBPB flush on BPF JIT memory reuse while Spectre-v2 mitigations are in useCVE-2026-64507 · Linux kernel x86/bugs (IBPB flush on BPF JIT allocation)Unscored
- Linux kernel BPF JIT: reused JIT memory can inherit branch predictions from the program that freed itCVE-2026-64508 · Linux kernel BPF JIT allocator (branch-predictor flush on JIT memory reuse)Unscored
- Linux i915 GPU kernel driver (context SSEU parameter): NULL dereference reachable by setting a context engine slotCVE-2026-68243 · Linux i915 GPU kernel driver (context SSEU parameter)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.