Vulnerability Description
Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. Memory-wise small enough guests may still be okay to run.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://xenbits.xenproject.org/xsa/advisory-495.html
- http://www.openwall.com/lists/oss-security/2026/07/28/12
- http://xenbits.xen.org/xsa/advisory-495.html
FAQ
What is CVE-2026-42493?
CVE-2026-42493 is a vulnerability with a CVSS score of 7.5 (HIGH). Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives (HVM/PVH: HAP, PV:...
How severe is CVE-2026-42493?
CVE-2026-42493 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42493?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.