PT-2026-27499 · Linux+1 · Linux Kernel+1

Published

2026-01-01

·

Updated

2026-04-25

·

CVE-2026-31788

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Xen privcmd driver allows user space processes to issue arbitrary hypercalls. Normally, access is limited to root and the hypervisor denies hypercalls affecting other domains. However, when a guest is booted using secure boot, an unprivileged domU process could potentially modify kernel memory contents, breaking the secure boot feature. The issue arises because the privcmd driver can be used to issue hypercalls from user space, even in unprivileged domUs. The driver can be locked down to allow only hypercalls targeting a specific domain, but this mode can be activated from user land. The target domain can be obtained from Xenstore. PV, PVH and HVM guests running Linux using secure boot are vulnerable.
Recommendations Restrict the privcmd driver to a specific target domain from the beginning, obtained from Xenstore, when not running in dom0.

Exploit

Fix

Related Identifiers

CVE-2026-31788
ECHO-3D3F-9144-B734
OESA-2026-1862
OESA-2026-1863
OESA-2026-1864
OESA-2026-1950
OPENSUSE-SU-2026:20572-1
SUSE-SU-2026:1573-1
SUSE-SU-2026:1643-1
SUSE-SU-2026:1661-1
SUSE-SU-2026:21114-1
SUSE-SU-2026:21123-1
SUSE-SU-2026:21237-1
SUSE-SU-2026:21255-1
SUSE-SU-2026:21352-1
SUSE-SU-2026:21361-1

Affected Products

Linux Kernel
Xen