The Xen Project disclosed XSA-505 for CVE-2026-62432, a race condition in event channel handling between EVTCHNOP_expand_array and EVTCHNOP_reset that affects Xen versions 4.5 and later. The flaw stems from checking whether FIFO event channels are enabled without holding the proper lock, which can result in a NULL pointer dereference inside the hypervisor.
Xen said a malicious guest can exploit the bug to crash the host and cause denial of service: HVM guests on x86 HVM, PVH, and ARM are able to crash Xen, while a malicious x86 PV guest could likely also trigger memory corruption or possibly privilege escalation. Xen reported that versions 4.4 and earlier are not affected, that no mitigations are available, and that remediation requires applying the vendor patch provided in xsa505.patch for xen-unstable and Xen 4.17 in line with the project's security advisory process.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Xen Security Advisory 505 v2 disclosed CVE-2026-62432, a race condition in event channel handling between EVTCHNOP_expand_array and EVTCHNOP_reset that can let a malicious guest crash Xen. The advisory said Xen versions 4.5 onward are vulnerable, no mitigations are available, and the issue is fixed by applying xsa505.patch for xen-unstable / Xen 4.17.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.