{"id":"ALPINE-CVE-2026-42492","details":"Xenstore, to have an up-to-date picture of the entire system, wants to\nknow of domains appearing and disappearing.  To make this more robust, a\nnew XEN_DOMCTL_get_domain_state was introduced.  The management of the\nbitmap underlying that operation is tied into the binding of the\nVIRQ_DOM_EXC virtual IRQ.  Unfortunately an error path there would tear\ndown the bitmap even in cases when it wasn't set up.  Unprivileged domains\ncan trigger that error path.","modified":"2026-09-14T16:18:08.188851712Z","published":"2026-07-28T13:18:32.123Z","upstream":["CVE-2026-42492"],"references":[{"type":"ADVISORY","url":"https://security.alpinelinux.org/vuln/CVE-2026-42492"}],"affected":[{"package":{"name":"xen","ecosystem":"Alpine:v3.24","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.21.2-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42492.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}