{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-62428","assignerOrgId":"23aa2041-22e1-471f-9209-9b7396fa234f","state":"PUBLISHED","assignerShortName":"XEN","dateReserved":"2026-07-14T10:28:12.655Z","datePublished":"2026-07-28T12:32:07.573Z","dateUpdated":"2026-07-28T16:33:28.183Z"},"containers":{"cna":{"title":"grant-table: type confusion in grant-copy","datePublic":"2026-07-28T12:00:00.000Z","descriptions":[{"lang":"en","value":"When grant-copy operations are processed, the respective grant may or may\nnot already be in use by another operation (a mapping or another copy).\nFor all copy operations the referenced guest frame is looked up.  When\nanother operation is already active for the grant (the grant is \"pinned\"),\nwhat is being supplied back to actually carry out permission checks and\ncopy operation may not be consistent: The permission check may be carried\nout on a page different from the one involved in the copy."}],"impacts":[{"descriptions":[{"lang":"en","value":"An unprivileged guest may be able to elevate its privileges to that of the\nhost.  Information leaks and Denial of Service (DoS) are possible as well."}]}],"affected":[{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-500"}]}],"configurations":[{"lang":"en","value":"All Xen versions from 4.2 onwards are vulnerable.  Xen versions 4.1 and\nearlier are not vulnerable.\n\nXen versions 4.13 and newer offer a way to build Xen without grant table\nsupport.  Such hypervisors (CONFIG_GRANT_TABLE turned off) are not\nvulnerable."}],"workarounds":[{"lang":"en","value":"There is no known mitigation."}],"credits":[{"lang":"en","type":"finder","value":"This issue was discovered by Roman S."}],"references":[{"url":"https://xenbits.xenproject.org/xsa/advisory-500.html"}],"providerMetadata":{"orgId":"23aa2041-22e1-471f-9209-9b7396fa234f","shortName":"XEN","dateUpdated":"2026-07-28T12:32:07.573Z"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://xenbits.xen.org/xsa/advisory-500.html"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/28/16"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-07-28T16:33:28.183Z"}},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-367","lang":"en","description":"CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition"}]}],"metrics":[{"cvssV3_1":{"scope":"CHANGED","version":"3.1","baseScore":7.8,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"HIGH","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-07-28T15:10:28.542416Z","id":"CVE-2026-62428","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-28T15:10:53.004Z"}}]}}