CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6424-1 xen - security update

unknownCVE-2025-10263CVE-2025-54505CVE-2025-54518CVE-2026-23554CVE-2026-23555CVE-2026-23556
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, information disclosure or denial of service. https://security-tracker.debian.org/tracker/DSA-6424-1

CSIRTS triage

What
Multiple vulnerabilities in the Xen hypervisor permit privilege escalation, information disclosure, or denial of service.
Who is affected
Xen hypervisor deployments of unspecified versions.
Urgency
Moderate urgency; privilege escalation and information disclosure capabilities warrant prompt remediation.
Action
Apply security updates from Debian (DSA-6424-1) or consult Xen project advisories for affected versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Xen

Get an email when a new Xen advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-09
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00335.html

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-10263coverage & exploitation statusNVD · CVE.org
CVE-2025-54505coverage & exploitation statusNVD · CVE.org
CVE-2025-54518coverage & exploitation statusNVD · CVE.org
CVE-2026-23554coverage & exploitation statusNVD · CVE.org
CVE-2026-23555coverage & exploitation statusNVD · CVE.org
CVE-2026-23556coverage & exploitation statusNVD · CVE.org
CVE-2026-23557coverage & exploitation statusNVD · CVE.org
CVE-2026-23558coverage & exploitation statusNVD · CVE.org
CVE-2026-42487coverage & exploitation statusNVD · CVE.org
CVE-2026-42488coverage & exploitation statusNVD · CVE.org
CVE-2026-42489coverage & exploitation statusNVD · CVE.org
CVE-2026-42490coverage & exploitation statusNVD · CVE.org
CVE-2026-42493coverage & exploitation statusNVD · CVE.org
CVE-2026-42494coverage & exploitation statusNVD · CVE.org
CVE-2026-42495coverage & exploitation statusNVD · CVE.org
CVE-2026-62423coverage & exploitation statusNVD · CVE.org
CVE-2026-62424coverage & exploitation statusNVD · CVE.org
CVE-2026-62425coverage & exploitation statusNVD · CVE.org
CVE-2026-62426coverage & exploitation statusNVD · CVE.org
CVE-2026-62427coverage & exploitation statusNVD · CVE.org
CVE-2026-62428coverage & exploitation statusNVD · CVE.org
CVE-2026-62429coverage & exploitation statusNVD · CVE.org
CVE-2026-62430coverage & exploitation statusNVD · CVE.org
CVE-2026-62431coverage & exploitation statusNVD · CVE.org
CVE-2026-62432coverage & exploitation statusNVD · CVE.org
CVE-2026-62433coverage & exploitation statusNVD · CVE.org
CVE-2026-62434coverage & exploitation statusNVD · CVE.org
CVE-2026-62435coverage & exploitation statusNVD · CVE.org
CVE-2026-62436coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Debian Security Advisories