XenStore Node Count Leak Enables Quota Bypass on Domain Reuse
CVE-2026-23556 Published on July 9, 2026

oxenstored keeps quota related use counts across domain destruction
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.

NVD

Weakness Type

Improper Preservation of Permissions

The software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.


Products Associated with CVE-2026-23556

Want to know whenever a new CVE is published for Citrix Xen Xen? stack.watch will email you.

 

Affected Versions

oxenstored Version all is affected by CVE-2026-23556