openSUSE Releases Important Xen Patches for Multiple Vulnerabilities

openSUSE Releases Important Xen Patches for Multiple Vulnerabilities

First seen 10 Jun 2026, 19:32 UTC Linuxsecurity 93% similarity 57.9

Article Content

Browse articles
ThreatCluster

On June 10, 2026, openSUSE released updates addressing critical vulnerabilities in Xen, specifically CVE-2026-42487, CVE-2026-42488, CVE-2026-42489, and CVE-2026-42490. These vulnerabilities include issues such as x86 HVM I/O port list traversal and mismatched mapcache metadata, which could allow for unauthorized access and potential abuse of domctl locks. The vulnerabilities affect systems utilizing the Xen hypervisor, with CVSS scores ranging from 5.3 to 8.8, indicating varying levels of severity. The updates are crucial for maintaining the security of affected systems, and administrators are urged to apply the patches promptly to mitigate risks. The release includes two separate advisories, SUSE-2026-2328 and SUSE-2026-2329, both issued on the same day.

Key Points: • openSUSE released critical patches for Xen vulnerabilities on June 10, 2026. • The vulnerabilities include CVE-2026-42487, CVE-2026-42488, CVE-2026-42489, and CVE-2026-42490. • Administrators are urged to apply the patches immediately to secure affected systems.

ThreatCluster AI

Timeline

2026-06-10
openSUSE releases updates for Xen vulnerabilities
Patches addressing CVE-2026-42487, CVE-2026-42488, CVE-2026-42489, and CVE-2026-42490 were released to fix critical issues in the Xen hypervisor.
Linuxsecurity
2026-06-10
Multiple advisories issued for Xen vulnerabilities
SUSE-2026-2328 and SUSE-2026-2329 advisories were published, detailing the vulnerabilities and their CVSS scores.
Linuxsecurity

Community

Browse all →