take excessively long and therefore would need preemption, has turned out
overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly
available, the decision was to deprecate the functionality, while still
retaining it for people to use at their own (security) risk. Memory-wise
small enough guests may still be okay to run.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this vulnerability. There's no mitigation available for PV guests. This is because shadow mode, if support is enabled in the hypervisor, could be engaged at any time. Note that without shadow mode built into Xen, guests not properly dealing with L1TF will simply be crashed instead.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-495.html |
|
Tue, 28 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. Memory-wise small enough guests may still be okay to run. | |
| Title | x86 shadow paging is deprecated | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2026-07-28T16:33:23.792Z
Reserved: 2026-04-27T14:20:24.139Z
Link: CVE-2026-42493
Updated: 2026-07-28T16:33:23.792Z
No data.
No data.
OpenCVE Enrichment
No data.