VSA-2026-024: Multiple Xen XSAs assessed as not impacting Vates products
| Published | Updated | Severity | CVSS 4.0 | Affected products |
|---|---|---|---|---|
| 2026-07-28 | 2026-07-28 | ⚪ N/A | Not applicable | - None |
Multiple Xen Security Advisories were recently published. Three of them are assessed as not impacting Vates products (XCP-ng and Xen Orchestra). This advisory summarizes those XSAs.
Summary
The following Xen Security Advisories were assessed and determined to not impact Vates products:
- XSA-495 (CVE-2026-42493): x86 shadow paging is deprecated
- XSA-496 (CVE-2026-42492): vIRQ event channel binding may break Xenstore
- XSA-508: pygrub is only supported in de-privileged mode
Details
XSA-495: x86 shadow paging is deprecated (CVE-2026-42493)
Xen Project is deprecating x86 shadow paging support due to complexity and security risks and now recommends moving to alternatives instead. Check XSA-495 for more details.
Why not impacting: XCP-ng disabled shadow paging in 8.3.
XSA-496: vIRQ event channel binding may break Xenstore (CVE-2026-42492)
An error path in the VIRQ_DOM_EXC binding could tear down the domain state bitmap, potentially affecting Xenstore operation and causing a denial of service.
Why not impacting: This issue only affects Xen 4.21 and later. XCP-ng 8.3 uses Xen 4.17, which is not vulnerable.
XSA-508: pygrub is only supported in de-privileged mode
A guest using pygrub can escalate its privileges to those of dom0 due to issues in the libfsimage FS driver. This is addressed by running pygrub in de-privileged mode.
Why not impacting: XCP-ng always runs pygrub in de-privileged mode.
Affected Versions
- XCP-ng 8.3: Not affected.
Resolution
No action is required for the XSAs listed above. For the remaining XSAs that do impact Vates products, please refer to the individual VSA advisories listed in the References section.