Xen disclosed XSA-499 v2 for two vulnerabilities, CVE-2026-62426 and CVE-2026-62427, affecting sysctl and platform operations that rely on system-wide locks for privileged management tasks. The flaws stem from unfair lock acquisition, allowing a less privileged entity to repeatedly obtain locks needed by the control domain or a Xenstore domain and block other operations that cannot safely run in parallel.
In deployments using XSM/Flask, Xen said some lock acquisitions can occur before permission checks, worsening the impact and enabling denial-of-service conditions that may extend to the entire host. Xen reported that all versions from 4.0 onward are confirmed vulnerable, earlier releases may also be affected, and there is no known mitigation beyond applying the vendor patches; environments using Flask also need a default policy adjustment, with corresponding updates required for custom policies.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Xen disclosed XSA-499 version 2 covering two vulnerabilities, CVE-2026-62426 and CVE-2026-62427, involving unfair acquisition of sysctl and platform-op locks. The advisory says a less privileged entity could abuse these conditions to stall equally or more privileged entities, potentially causing denial of service up to the entire host, and recommends applying patches plus a default Flask policy adjustment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.