Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 42 Xen Critical Use After Free DoS Advisory 2026-f04da48123

fedora
Calendar Grey April 1, 2026
Dist Fedora Esm H88
Xen 4.19.5 patch addresses critical use after free and DoS threats on Fedora 42. Update recommended immediately.
update to xen 4.19.5 Use after free of paging structures in EPT [XSA-480, CVE-2026-23554] Xenstored DoS by unprivileged domain [XSA-481, CVE-2026-23555]

Summary

This package contains the XenD daemon and xm command line

tools, needed to manage virtual machines running under the

Xen hypervisor

Update Information:

update to xen 4.19.5 Use after free of paging structures in EPT [XSA-480, CVE-2026-23554] Xenstored DoS by unprivileged domain [XSA-481, CVE-2026-23555]

Change Log

* Fri Mar 27 2026 Michael Young - 4.19.5-1 - update to xen 4.19.5 remove patches now included or superceded upstream * Wed Mar 18 2026 Michael Young - 4.19.4-3 - Use after free of paging structures in EPT [XSA-480, CVE-2026-23554] - Xenstored DoS by unprivileged domain [XSA-481, CVE-2026-23555]

References


[ 1 ] Bug #2450273 - CVE-2026-23554 xen: Xen: Information disclosure and potential privilege escalation via use-after-free in EPT paging [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2450273

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f04da48123' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: xen
Product: Fedora 42
Version: 4.19.5
Release: 1.fc42
Summary: Xen is a virtual machine monitor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here