CVE-2026-45890
📛 CVE Title
xen-netback: reject zero-queue configuration from guest
Description
In the Linux kernel, the following vulnerability has been resolved: xen-netback: reject zero-queue configuration from guest A malicious or buggy Xen guest can write "0" to the xenbus key "multi-queue-num-queues". The connect() function in the backend only validates the upper bound (requested_num_queues > xenvif_max_queues) but not zero, allowing requested_num_queues=0 to reach vzalloc(array_size(0, sizeof(struct xenvif_queue))), which triggers WARN_ON_ONCE(!size) in __vmalloc_node_range(). On systems with panic_on_warn=1, this allows a guest-to-host denial of service. The Xen network interface specification requires the queue count to be "greater than zero". Add a zero check to match the validation already present in xen-blkback, which has included this guard since its multi-queue support was added.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- high
- CVSS score
- 8.4 / 10
- CVSS vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 8.4 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-05-13
- Published
- 2026-05-27 12:17 UTC
- Last updated
- 2026-05-27 12:17 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45890.json
- Linked Threat
- CVE-2026-45890 — CVE-2026-45890
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-27 14:17:03 UTC
- NVD last modified
- 2026-06-25 21:13:36 UTC
- NVD CVSS v3.1
- 5.5 / 10 MEDIUM source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0012 (probability of exploitation in next 30 days)
- EPSS percentile
- 2.40% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD / KEV / EPSS data refreshed 2026-07-27 11:54 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32356 - Assigner
- Linux
- Published
- May 27, 2026, 12:17:01 PM
- Updated
- May 27, 2026, 12:17:01 PM
- EUVD base score
- 0.0 / 10
- EUVD-reported EPSS
- 0.1200
- Vendors
- Linux
- Products
-
Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <ce66d6786de45b7ed9cbbdc0988054bf09e58f54)Linux (patch: 6.6.128)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <ec4859ac5c933e3315543a61adc1ca4358006a41)Linux (patch: 6.12.75)Linux (patch: 5.15.202)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <d99f69ddc70fd9f4b8148add62209a1a8eb5c615)Linux (3.16)Linux (patch: 6.18.14)Linux (patch: 7.0)Linux (patch: 0)Linux (patch: 6.19.4)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <2993e0f904c45f8af12917344bb1cac7ccd05a60)Linux (patch: 6.1.165)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <787bfa423228c4b02ba3368128f625d579085353)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <6d1dc8014334c7fb25719999bca84d811e60a559)Linux (patch: 5.10.252)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <654780dee9eae419e1648ea58462c4efe54518fa)Linux (8d3d53b3e43363e79ab9a9ecc149b06c1314b25d <88b0fced1bbbfdb356a007592604008ffc93a6a1)
- Aliases
-
GHSA-jc43-3m97-6p35
ENISA description: In the Linux kernel, the following vulnerability has been resolved: xen-netback: reject zero-queue configuration from guest A malicious or buggy Xen guest can write "0" to the xenbus key "multi-queue-num-queues". The connect() function in the backend only validates the upper bound (requested_num_queues > xenvif_max_queues) but not zero, allowing requested_num_queues=0 to reach vzalloc(array_size(0, sizeof(struct xenvif_queue))), which triggers WARN_ON_ONCE(!size) in __vmalloc_node_range(). On systems with panic_on_warn=1, this allows a guest-to-host denial of service. The Xen network interface specification requires the queue count to be "greater than zero". Add a zero check to match the validation already present in xen-blkback, which has included this guard since its multi-queue support was added.
EUVD references (8)
- https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60
- https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353
- https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54
- https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1
- https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41
- https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa
- https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615
- https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected),
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d (affected)
|
— |
| Linux | Linux |
3.16 (affected),
0 (unaffected),
5.10.252 (unaffected),
5.15.202 (unaffected),
6.1.165 (unaffected),
6.6.128 (unaffected),
6.12.75 (unaffected),
6.18.14 (unaffected),
6.19.4 (unaffected),
7.0 (unaffected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendor references (8)
References embedded in the original CVE record by the assigning CNA.
- https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60
- https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353
- https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54
- https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1
- https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41
- https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa
- https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615
- https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559
Web references (11)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60 tenable:git.kernel.org
- https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa tenable:git.kernel.org
- https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559 tenable:git.kernel.org
- https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353 tenable:git.kernel.org
- https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1 tenable:git.kernel.org
- https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54 tenable:git.kernel.org
- https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615 tenable:git.kernel.org
- https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41 tenable:git.kernel.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45890 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45890 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (8)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
Remediations (19)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.gridinsoft.com
CVE - 2026 -41089 in Windows Netlogon is now reported as actively exploited. Patch domain controllers and check LSASS, Netlogon, and authentication logs.
2026-06-04 00:16 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-04 00:16 UTC -
web:kudelskisecurity.com
Immediate Patching: Apply the May 2026 Patch Tuesday security update from Microsoft to all affected Windows Server versions. This is the only complete mitigation for CVE - 2026 -41089.
2026-06-04 00:16 UTC -
web:learn.microsoft.com
As of November 11, 2025, Home and Pro editions of Windows 11, version 23H2 have reached end of servicing. Enterprise and Education editions of version 23H2 will continue to receive monthly security updates until November 10, 2026 .
2026-06-04 00:16 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-04 00:16 UTC -
web:orca.security
Critical Netlogon RCE CVE - 2026 -41089 puts Windows Server domain controllers at risk. Use Orca Security to detect unpatched instances and protect your AD.
2026-06-04 00:16 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 00:16 UTC -
web:thecyberexpress.com
Threat actors are reportedly exploiting CVE - 2026 -41089, a critical Windows Netlogon vulnerability enabling unauthenticated remote code execution.
2026-06-04 00:16 UTC -
web:windowsreport.com
Belgium's cybersecurity agency warns attackers are actively exploiting the critical Windows Netlogon vulnerability CVE - 2026 -41089.
2026-06-04 00:16 UTC -
web:www.helpnetsecurity.com
CVE - 2026 -41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild.
2026-06-04 00:16 UTC -
web:cybersecuritynews.com
Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.
2026-06-19 02:27 UTC -
web:tech.yahoo.com
Microsoft has confirmed an emergency security update as CISA warns that two new Defender zero-days are being exploited by attackers.
2026-06-19 02:27 UTC -
web:thehackernews.com
Microsoft patches 59 vulnerabilities, including six actively exploited zero-days, with CISA mandating urgent federal remediation .
2026-06-19 02:27 UTC -
web:www.computerworld.com
Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...
2026-06-19 02:27 UTC -
web:www.csoonline.com
Microsoft highlighted six new and actively exploited vulnerabilities among the 60 fixes issued in today's February Patch Tuesday releases.
2026-06-19 02:27 UTC -
web:www.csoonline.com
Microsoft released emergency fixes for two zero-day vulnerabilities in the malware protection components of Microsoft Defender. The flaws allow local attackers to gain system-level privileges or ...
2026-06-19 02:27 UTC -
web:www.malwarebytes.com
Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
2026-06-19 02:27 UTC -
web:www.microsoft.com
Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.
2026-06-19 02:27 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-19 02:27 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-45890.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/net/xen-netback/xenbus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2993e0f904c45f8af12917344bb1cac7ccd05a60",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "787bfa423228c4b02ba3368128f625d579085353",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "ce66d6786de45b7ed9cbbdc0988054bf09e58f54",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "88b0fced1bbbfdb356a007592604008ffc93a6a1",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "ec4859ac5c933e3315543a61adc1ca4358006a41",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "654780dee9eae419e1648ea58462c4efe54518fa",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "d99f69ddc70fd9f4b8148add62209a1a8eb5c615",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
},
{
"lessThan": "6d1dc8014334c7fb25719999bca84d811e60a559",
"status": "affected",
"version": "8d3d53b3e43363e79ab9a9ecc149b06c1314b25d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/net/xen-netback/xenbus.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"lessThan": "3.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "3.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "3.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen-netback: reject zero-queue configuration from guest\n\nA malicious or buggy Xen guest can write \"0\" to the xenbus key\n\"multi-queue-num-queues\". The connect() function in the backend only\nvalidates the upper bound (requested_num_queues > xenvif_max_queues)\nbut not zero, allowing requested_num_queues=0 to reach\nvzalloc(array_size(0, sizeof(struct xenvif_queue))), which triggers\nWARN_ON_ONCE(!size) in __vmalloc_node_range().\n\nOn systems with panic_on_warn=1, this allows a guest-to-host denial\nof service.\n\nThe Xen network interface specification requires\nthe queue count to be \"greater than zero\".\n\nAdd a zero check to match the validation already present\nin xen-blkback, which has included this\nguard since its multi-queue support was added."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-27T12:17:01.466Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60"
},
{
"url": "https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353"
},
{
"url": "https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54"
},
{
"url": "https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1"
},
{
"url": "https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41"
},
{
"url": "https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa"
},
{
"url": "https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615"
},
{
"url": "https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559"
}
],
"title": "xen-netback: reject zero-queue configuration from guest",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45890",
"datePublished": "2026-05-27T12:17:01.466Z",
"dateReserved": "2026-05-13T15:03:33.083Z",
"dateUpdated": "2026-05-27T12:17:01.466Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}