domain destruction has already started. The cleaning up of that
configuration information is not synchronized with its retrieval by a
device model controlling the guest.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
On x86, running only PV or PVH guests will avoid the vulnerability. Not enabling vNUMA for HVM guests will also avoid the vulnerability.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-502.html |
|
Tue, 28 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xen
Xen xen |
|
| Vendors & Products |
Xen
Xen xen |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest. | |
| Title | vNUMA domain cleanup may race other operations | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2026-07-28T16:33:29.286Z
Reserved: 2026-07-14T10:28:12.655Z
Link: CVE-2026-62429
Updated: 2026-07-28T16:33:29.286Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T20:00:10Z