{"api_version":"1","generated_at":"2026-08-24T06:22:13+00:00","cve":"CVE-2026-42493","urls":{"html":"https://cve.report/CVE-2026-42493","api":"https://cve.report/api/cve/CVE-2026-42493.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-42493","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-42493"},"summary":{"title":"x86 shadow paging is deprecated","description":"Addressing certain issues, in particular related to operations which may\ntake excessively long and therefore would need preemption, has turned out\noverly costly.  Since alternatives (HVM/PVH: HAP, PV: shim) are commonly\navailable, the decision was to deprecate the functionality, while still\nretaining it for people to use at their own (security) risk.  Memory-wise\nsmall enough guests may still be okay to run.","state":"PUBLISHED","assigner":"XEN","published_at":"2026-07-28 13:18:32","updated_at":"2026-07-28 17:16:39"},"problem_types":["CWE-400","CWE-400 CWE-400 Uncontrolled Resource Consumption"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/28/12","name":"http://www.openwall.com/lists/oss-security/2026/07/28/12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://xenbits.xen.org/xsa/advisory-495.html","name":"http://xenbits.xen.org/xsa/advisory-495.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://xenbits.xenproject.org/xsa/advisory-495.html","name":"https://xenbits.xenproject.org/xsa/advisory-495.html","refsource":"security@xen.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-42493","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42493","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Xen","product":"Xen","version":"unknown consult Xen advisory XSA-495","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this\nvulnerability.\n\nThere's no mitigation available for PV guests.  This is because shadow\nmode, if support is enabled in the hypervisor, could be engaged at any\ntime.  Note that without shadow mode built into Xen, guests not properly\ndealing with L1TF will simply be crashed instead.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"42493","cve":"CVE-2026-42493","epss":"0.004740000","percentile":"0.383970000","score_date":"2026-07-29","updated_at":"2026-07-30 00:09:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-07-28T16:33:23.792Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://xenbits.xen.org/xsa/advisory-495.html"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/28/12"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-42493","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-28T15:58:19.075241Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-28T15:58:45.484Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-495"}]}],"configurations":[{"lang":"en","value":"All x86 systems with builds of Xen having SHADOW_PAGING=y are affected.\nNote that prior to Xen 4.7 this control didn't exist, and all builds of\nXen would be affected.  (Strictly speaking Xen 4.6 had a different, harder\nto use mechanism to disable shadow paging support: One could pass\n\"shadow-paging=n\" on the make command line.)"}],"datePublic":"2026-07-28T12:00:00.000Z","descriptions":[{"lang":"en","value":"Addressing certain issues, in particular related to operations which may\ntake excessively long and therefore would need preemption, has turned out\noverly costly.  Since alternatives (HVM/PVH: HAP, PV: shim) are commonly\navailable, the decision was to deprecate the functionality, while still\nretaining it for people to use at their own (security) risk.  Memory-wise\nsmall enough guests may still be okay to run."}],"impacts":[{"descriptions":[{"lang":"en","value":"An unprivileged guest may be able to cause Denial of Service (DoS)\naffecting the entire host."}]}],"providerMetadata":{"dateUpdated":"2026-07-28T12:31:11.950Z","orgId":"23aa2041-22e1-471f-9209-9b7396fa234f","shortName":"XEN"},"references":[{"url":"https://xenbits.xenproject.org/xsa/advisory-495.html"}],"title":"x86 shadow paging is deprecated","workarounds":[{"lang":"en","value":"Running HVM and PVH in Hardware Assisted Paging (HAP) mode will avoid this\nvulnerability.\n\nThere's no mitigation available for PV guests.  This is because shadow\nmode, if support is enabled in the hypervisor, could be engaged at any\ntime.  Note that without shadow mode built into Xen, guests not properly\ndealing with L1TF will simply be crashed instead."}]}},"cveMetadata":{"assignerOrgId":"23aa2041-22e1-471f-9209-9b7396fa234f","assignerShortName":"XEN","cveId":"CVE-2026-42493","datePublished":"2026-07-28T12:31:11.950Z","dateReserved":"2026-04-27T14:20:24.139Z","dateUpdated":"2026-07-28T16:33:23.792Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-28 13:18:32","lastModifiedDate":"2026-07-28 17:16:39","problem_types":["CWE-400","CWE-400 CWE-400 Uncontrolled Resource Consumption"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-28T15:58:19.075241Z","id":"CVE-2026-42493","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"42493","Ordinal":"1","Title":"x86 shadow paging is deprecated","CVE":"CVE-2026-42493","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"42493","Ordinal":"1","NoteData":"Addressing certain issues, in particular related to operations which may\ntake excessively long and therefore would need preemption, has turned out\noverly costly.  Since alternatives (HVM/PVH: HAP, PV: shim) are commonly\navailable, the decision was to deprecate the functionality, while still\nretaining it for people to use at their own (security) risk.  Memory-wise\nsmall enough guests may still be okay to run.","Type":"Description","Title":"x86 shadow paging is deprecated"}]}}}