{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T21:23:38.578","vulnerabilities":[{"cve":{"id":"CVE-2026-23553","sourceIdentifier":"security@xen.org","published":"2026-01-28T16:16:16.853","lastModified":"2026-06-17T10:21:46.190","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In the context switch logic Xen attempts to skip an IBPB in the case of\na vCPU returning to a CPU on which it was the previous vCPU to run.\nWhile safe for Xen's isolation between vCPUs, this prevents the guest\nkernel correctly isolating between tasks.  Consider:\n\n 1) vCPU runs on CPU A, running task 1.\n 2) vCPU moves to CPU B, idle gets scheduled on A.  Xen skips IBPB.\n 3) On CPU B, guest kernel switches from task 1 to 2, issuing IBPB.\n 4) vCPU moves back to CPU A.  Xen skips IBPB again.\n\nNow, task 2 is running on CPU A with task 1's training still in the BTB."},{"lang":"es","value":"En la lógica de conmutación de contexto, Xen intenta omitir un IBPB en el caso de que una vCPU regrese a una CPU en la que fue la vCPU anterior en ejecutarse. Si bien es seguro para el aislamiento de Xen entre vCPUs, esto impide que el kernel invitado aísle correctamente entre tareas. Considere:\n\n1) La vCPU se ejecuta en la CPU A, ejecutando la tarea 1.\n2) La vCPU se mueve a la CPU B, el proceso inactivo se programa en A. Xen omite el IBPB.\n3) En la CPU B, el kernel invitado cambia de la tarea 1 a la 2, emitiendo un IBPB.\n4) La vCPU regresa a la CPU A. Xen omite el IBPB de nuevo.\n\nAhora, la tarea 2 se está ejecutando en la CPU A con el entrenamiento de la tarea 1 todavía en el BTB."}],"affected":[{"source":"security@xen.org","affectedData":[{"vendor":"Xen","product":"Xen","defaultStatus":"unknown","versions":[{"version":"consult Xen advisory XSA-479","status":"unknown"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":2.9,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.4,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-28T16:40:38.385640Z","id":"CVE-2026-23553","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-665"},{"lang":"en","value":"CWE-693"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:*","versionStartIncluding":"4.6.0","matchCriteriaId":"4B8D71AF-016B-49EF-AE2B-95DEDE3BE3C3"}]}]}],"references":[{"url":"https://xenbits.xenproject.org/xsa/advisory-479.html","source":"security@xen.org","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2026/01/27/3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Mitigation","Patch","Third Party Advisory"]},{"url":"http://xenbits.xen.org/xsa/advisory-479.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"]}]}}]}