CVE-2026-23557
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/05/2026
Last modified:
19/05/2026
Description
Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES<br />
command within a transaction due to an assert() triggering.<br />
<br />
In case xenstored was built with NDEBUG #defined nothing bad will<br />
happen, as assert() is doing nothing in this case. Note that the<br />
default is not to define NDEBUG for xenstored builds even in release<br />
builds of Xen.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | 4.2.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



