Skip to main content

Security advisories (VSA)

All published Vates Security Advisories, one page per advisory with the impact, affected versions, mitigation and the packages fixing the issue. Search by VSA identifier, CVE or XSA number, or filter by severity, product and year; you can also browse by year in the sidebar.

43 advisories, showing 1-10

AdvisoryPublishedSeverityAffected productsReferences
VSA-2026-034PoD doesn't try to reclaim special pages (CVE-2026-62434 / XSA-507)2026-07-28ImportantXCP-ng 8.3XSA-507, CVE-2026-62434
VSA-2026-033incorrect buffer checks for DM_OP hypercalls (CVE-2026-62433 / XSA-506)2026-07-28LowXCP-ng 8.3XSA-506, CVE-2026-62433
VSA-2026-032evtchn race between FIFO expand and reset (CVE-2026-62432 / XSA-505)2026-07-28ImportantXCP-ng 8.3XSA-505, CVE-2026-62432
VSA-2026-031Viridian STIMER division by zero (CVE-2026-62431 / XSA-504)2026-07-28ImportantXCP-ng 8.3XSA-504, CVE-2026-62431
VSA-2026-030out-of-bounds read in vRTC emulation (CVE-2026-62430 / XSA-503)2026-07-28ModerateXCP-ng 8.3XSA-503, CVE-2026-62430
VSA-2026-029vNUMA domain cleanup may race other operations (CVE-2026-62429 / XSA-502)2026-07-28LowXCP-ng 8.3XSA-502, CVE-2026-62429
VSA-2026-028grant-table version change racing with other operations (CVE-2026-62435, CVE-2026-62436 / XSA-501)2026-07-28ImportantXCP-ng 8.3XSA-501, CVE-2026-62435, CVE-2026-62436
VSA-2026-027grant-table type confusion in grant-copy (CVE-2026-62428 / XSA-500)2026-07-28CriticalXCP-ng 8.3XSA-500, CVE-2026-62428
VSA-2026-026sysctl and platform-op locks open to abuse (CVE-2026-62426, CVE-2026-62427 / XSA-499)2026-07-28LowXCP-ng 8.3XSA-499, CVE-2026-62426, CVE-2026-62427
VSA-2026-025buffer overruns in libfsimage iso9660 handling (CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425 / XSA-497)2026-07-28ModerateXCP-ng 8.3XSA-497, XSA-443, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425
Page 1 of 5

Subscribe

Security teams can follow VSA publications without watching this page:

  • RSS feed: /vsa/rss.xml
  • Machine-readable index: /vsa/index.json, the same data that powers the list above, for scripts and vulnerability management tooling.