XenStore Node Count Leak Enables Quota Bypass on Domain Reuse
CVE-2026-23556 Published on July 9, 2026
oxenstored keeps quota related use counts across domain destruction
When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.
When the domain ID is eventually reused, the new domain can create fewer
nodes before beeing deemed to be over quota.
Weakness Type
Improper Preservation of Permissions
The software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Products Associated with CVE-2026-23556
Want to know whenever a new CVE is published for Citrix Xen Xen? stack.watch will email you.