Xen Hypervisor Unchecked Buffer Count in DM_OP leads to stack corruption
CVE-2026-62433 Published on July 28, 2026
correct buffer checks for DM_OP hypercalls
Parts of the DM_OP handling code assumes the caller has provided the
required number of buffers for the given operation without any checking
being done. As a result, certain operations might access stack
rubble as structures are possibly uninitialized.
Vulnerability Analysis
CVE-2026-62433 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
Improper Initialization
The software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used. This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.
Products Associated with CVE-2026-62433
Want to know whenever a new CVE is published for Citrix Xen Xen? stack.watch will email you.