漏洞概述 漏洞编号: XSA-497 发布日期: 2026-07-28 12:00 更新日期: 2026-07-28 12:04 版本: 2 CVE编号: CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425 标题: buffer overruns in libifimage iso9660 handling 问题描述 libifimage 的 iso9660 驱动中的目录和 Rock Ridge / SUSP 遍历从攻击者控制的磁盘字段直接派生几个长度,而没有验证它们: 目录循环本身假设一个良好的记录长度。这是 CVE-2026-42494。 System Use 区域的计算可能会下溢。这是 CVE-2026-42495。 Rock Ridge 扩展循环假设一个良好的(内部)记录长度。这是 CVE-2026-62423。 Rock Ridge NR 记录处理假设一个良好的条目长度。这是 CVE-2026-62424。 Rock Ridge CE 记录处理假设一个良好的大小和偏移量。这是 CVE-2026-62425。 影响 使用 pygrub 的访客可以将其权限提升到域构建工具(即,通常,对主机的控制)。 如果引入的机制(见缓解部分)未启用,则访客只能提升到该受限上下文。 受影响系统 所有 Xen 版本从至少 3.2 开始都受到影响。旧版本尚未检查。 缓解措施 XSA-443 添加了一种以非特权方式运行 pygrub 的机制。使用此模式可以缓解漏洞。 确保访客不使用 pygrub 引导加载程序将避免此漏洞。 对于已知为 64 位并使用 grub2 作为引导加载程序的 PV 访客,pygrub 是 pygrub 的合适替代方案。 仅运行 HVM 或 PVH 访客将避免漏洞。 修复方案 应用附带的补丁可解决此问题。 注意:适用于已发布版本的补丁通常准备应用于稳定分支,并且可能不适用于最近发布的树。下游被鼓励在应用这些补丁之前先应用稳定分支顶部的补丁。 补丁文件 部署期间 在部署期间,允许部署上述补丁和/或缓解措施(或实质上相似的),即使在面向公众的系统上,即使有未受信任的访客用户和管理员。 但:禁止分发更新软件(仅向预披露列表中的其他成员分发)。 预披露列表成员希望部署显著不同的补丁和/或缓解措施,请联系 Xen 项目安全团队。 (注意:此期间部署通知在发布后保留,即使它不再适用。这是为了使社区能够了解 Xen 项目安全团队的决策过程。) 有关允许使用机密信息的更多信息,请查阅 Xen 项目社区商定的安全政策:http://www.xenproject.org/security-policy.html 发现者 此问题由 Syed Abdul Khaliq 发现。 签名 ``` -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Xen Security Advisory CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425 / XSA-497 version 2 buffer overruns in libifimage iso9660 handling UPDATES IN VERSION 2 Public release. ISSUE DESCRIPTION The directory and Rock Ridge / SUSP walk in libifimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them: The directory loop itself assumes a good record length. This is CVE-2026-42494. The calculation of the System Use area may underflow. This is CVE-2026-42495. The Rock Ridge extension loop assumes a good (inner) record length. This is CVE-2026-62423. The Rock Ridge NR record processing assumes a good entry length. This is CVE-2026-62424. The Rock Ridge CE record processing assumes a good size and offset. This is CVE-2026-62425. IMPACT A guest using pygrub can escalate its privilege to that of the domain construction tools (i.e., normally, to control of the host). If the mechanism introduced by XSA-443 (see the mitigation section below) is in use, then the guest can only escalate to this limited context. VULNERABLE SYSTEMS All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected. MITIGATION XSA-443 added a mechanism to run pygrub de-privileged. Using this mode will mitigate the vulnerability. Ensuring that guests do not use the pygrub bootloader will avoid this vulnerability. For cases where the PV guest is known to be 64bit, and uses grub2 as a bootloader, pygrub is a suitable alternative to pygrub. Running only HVM or PVH guests will avoid the vulnerability. CREDITS This issue was discovered by Syed Abdul Khaliq of Bugdore. RESOLUTION Applying the attached patch resolves this issue. Note that patches for released versions are generally prepared to apply to the stable branches, and may not apply cleanly to the most recent release tarballs. Downstreams are encouraged to have up to the tip of the stable branch before applying these patches. xs497.patch xen-unstable - Xen 4.17.x $ sha256sum xs497+ 0329c35a3732b9accd538d486e3a377ddc837fd102f61c18216cd277bf564 xs497.patch DEPLOYMENT DURING EMBARGO Deployment of the patches and/or mitigations described above (or others which are substantially similar) is permitted during the embargo, even on public-facing systems with untrusted guest users and administrators. But: Distribution of updated software is prohibited (except to other members of the pre-disclosure list). Pre-disclosure list members who wish to deploy significantly different patches and/or mitigations, please contact the Xen Project Security Team. (Note: this during-embargo deployment notice is retained in post-embargo publicly released Xen Project advisories, even though it is then no longer applicable. This is to enable the community to have oversight of the Xen Project Security Team's decisionmaking.) For more information about permissible uses of embargoed information, consult the Xen Project community's agreed Security Policy: http://www.xenproject.org/security-policy.html -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFEE1MILBRFHVkGpCng4UyVfok9X4Famopng9M8BnEB2W4u b37MAo3EPXKXCY2y9HNI06WU3D51LWYzD8W//rDg8bL0Ly0r382 P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjTv67r8F+2f051br95J//ou6Xr7g0yW0c1E8DK P4EcUeA8L1JF2ZP8D1xjT