Description
The EVTCHNOP_expand_array hypercall checks for whether FIFO event
channels are enabled, but without holding the correct lock. It can race
with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
channels are enabled, but without holding the correct lock. It can race
with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
There are no mitigations.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-505.html |
|
History
Tue, 28 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-362 | |
| Metrics |
cvssV3_1
|
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer. | |
| Title | evtchn: Race between FIFO expand and reset | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2026-07-28T16:33:32.509Z
Reserved: 2026-07-14T10:28:12.655Z
Link: CVE-2026-62432
Updated: 2026-07-28T16:33:32.509Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses