Xen Grant Table V2 Race Condition Vulnerability in Status Page Mapping

Vulnerability

A race condition vulnerability has been identified in Xen hypervisor versions 4.0 and later, affecting HVM and PVH guests that use grant table version 2. The vulnerability arises during a simultaneous grant table version change from v2 to v1 and the mapping of status pages into the guest's secondary page tables. This can lead to premature freeing of some status pages while their mappings are still being inserted, creating a potential for privilege escalation, information leaks, and denial-of-service conditions that could impact the entire host.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation, information leaks, and a denial-of-service condition that may affect the entire host.

Remediation

To address this vulnerability, use the 'gnttab=max-ver:1' hypervisor command line option or set the 'max_grant_version=1' guest configuration option for HVM and PVH guests. Patches are available for Xen 4.19.x and Xen 4.18.x through 4.17.x.

Added: May 19, 2026, 3:01 PM
Updated: May 19, 2026, 3:01 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
2.9
remediation
8.3
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.