{
  "affected": [
    {
      "ecosystem_specific": {},
      "package": {
        "ecosystem": "Alpine:v3.24",
        "name": "xen",
        "purl": "pkg:apk/alpine/xen?arch=source"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.21.2-r0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "Xenstore, to have an up-to-date picture of the entire system, wants to\nknow of domains appearing and disappearing.  To make this more robust, a\nnew XEN_DOMCTL_get_domain_state was introduced.  The management of the\nbitmap underlying that operation is tied into the binding of the\nVIRQ_DOM_EXC virtual IRQ.  Unfortunately an error path there would tear\ndown the bitmap even in cases when it wasn't set up.  Unprivileged domains\ncan trigger that error path.",
  "id": "ALPINE-CVE-2026-42492",
  "modified": "2026-08-27T22:18:03.545113605Z",
  "published": "2026-07-28T13:18:32.123Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security.alpinelinux.org/vuln/CVE-2026-42492"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-42492"
  ]
}