{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-42493","assignerOrgId":"23aa2041-22e1-471f-9209-9b7396fa234f","state":"PUBLISHED","assignerShortName":"XEN","dateReserved":"2026-04-27T14:20:24.139Z","datePublished":"2026-07-28T12:31:11.950Z","dateUpdated":"2026-07-28T16:33:23.792Z"},"containers":{"cna":{"title":"x86 shadow paging is deprecated","datePublic":"2026-07-28T12:00:00.000Z","descriptions":[{"lang":"en","value":"Addressing certain issues, in particular related to operations which may\ntake excessively long and therefore would need preemption, has turned out\noverly costly.  Since alternatives (HVM/PVH: HAP, PV: shim) are commonly\navailable, the decision was to deprecate the functionality, while still\nretaining it for people to use at their own (security) risk.  Memory-wise\nsmall enough guests may still be okay to run."}],"impacts":[{"descriptions":[{"lang":"en","value":"An unprivileged guest may be able to cause Denial of Service (DoS)\naffecting the entire host."}]}],"affected":[{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-495"}]}],"configurations":[{"lang":"en","value":"All x86 systems with builds of Xen having SHADOW_PAGING=y are affected.\nNote that prior to Xen 4.7 this control didn't exist, and all builds of\nXen would be affected.  (Strictly speaking Xen 4.6 had a different, harder\nto use mechanism to disable shadow paging support: One could pass\n\"shadow-paging=n\" on the make command line.)"}],"workarounds":[{"lang":"en","value":"Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this\nvulnerability.\n\nThere's no mitigation available for PV guests.  This is because shadow\nmode, if support is enabled in the hypervisor, could be engaged at any\ntime.  Note that without shadow mode built into Xen, guests not properly\ndealing with L1TF will simply be crashed instead."}],"references":[{"url":"https://xenbits.xenproject.org/xsa/advisory-495.html"}],"providerMetadata":{"orgId":"23aa2041-22e1-471f-9209-9b7396fa234f","shortName":"XEN","dateUpdated":"2026-07-28T12:31:11.950Z"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://xenbits.xen.org/xsa/advisory-495.html"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/28/12"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-07-28T16:33:23.792Z"}},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-400","lang":"en","description":"CWE-400 Uncontrolled Resource Consumption"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-07-28T15:58:19.075241Z","id":"CVE-2026-42493","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-28T15:58:45.484Z"}}]}}