Overview
What is CVE-2026-62432?
The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
Vulnerability intelligence
CVE-2026-62432 and is rated High severity with a CVSS score of 7.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.