Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

openSUSE Important xen Patch for Multiple Threats SUSE-2026-2329-1

suse
Calendar Grey June 10, 2026
Scroller Suse
Critical update for SUSE addressing multiple threats in xen with important patches to enhance security and stability.
An update that solves four vulnerabilities can now be installed.

Summary

## This update for xen fixes the following issues: * CVE-2026-42487: x86 HVM I/O port list traversal (bsc#1266952). * CVE-2026-42488: x86: mismatched mapcache metadata (bsc#1266955). * CVE-2026-42489,CVE-2026-42490: domctl lock open to abuse (bsc#1266953).

References

* bsc#1266952

* bsc#1266953

* bsc#1266955

Cross-

* CVE-2026-42487

* CVE-2026-42488

* CVE-2026-42489

* CVE-2026-42490

CVSS scores:

* CVE-2026-42487 ( SUSE ): 8.8

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

* CVE-2026-42487 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

* CVE-2026-42488 ( SUSE ): 8.7

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

* CVE-2026-42488 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

* CVE-2026-42489 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

* CVE-2026-42489 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H

* CVE-2026-42490 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2329-1
Release Date: 2026-06-10T07:39:36Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.