
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31788 is a privilege escalation vulnerability in the Linux kernel's Xen privcmd driver, tracked as XSA-482, that allows a root user process in an unprivileged guest domain (domU) to issue arbitrary hypercalls and modify kernel memory, thereby bypassing the secure boot protection mechanism. It affects the Linux kernel from version 2.6.37 through multiple stable branches, with fixed versions at 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, and 6.19.10. The vulnerability was published on March 25, 2026, and has a CVSS v3.1 base score of 8.2 (High) (Red Hat Advisory, Feedly).
The root cause is an incorrect privilege assignment (CWE-266) in the xen/privcmd driver, which permits root-level user-space processes in unprivileged domU guests to issue arbitrary hypercalls without restriction. Normally, the hypervisor denies hypercalls affecting other domains, but when secure boot is enabled, a root process can exploit the unrestricted privcmd interface to modify kernel memory contents, undermining the integrity guarantees of secure boot. The driver already supported a lockdown mode restricting hypercalls to a specific target domain, but this mode was only activatable from user land — not enforced automatically. The fix reads the target domain from Xenstore at driver open time (deferring if Xenstore is not yet ready) and restricts the privcmd driver to that domain from the outset when not running in dom0 (Red Hat Advisory, Xen Advisory).
A root user process within an unprivileged Xen guest domain can exploit this vulnerability to modify kernel memory and break the secure boot protection mechanism, potentially compromising the integrity of the entire virtualization environment. In the worst case, an attacker with root in a guest VM could gain broader influence over the hypervisor or other co-hosted domains, enabling privilege escalation beyond the guest boundary. Confidentiality, integrity, and availability are all rated as high impact with a changed scope, reflecting the potential for cross-domain effects (Red Hat Advisory, Feedly).
Update the Linux kernel to a patched version: 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, or 6.19.10, depending on the branch in use. Distributions including Debian, SUSE, Amazon Linux 2023, and openSUSE have released updated packages incorporating this fix (Red Hat Advisory, SUSE Advisory, Amazon Linux). As an interim workaround where patching is not immediately possible, restrict root access within unprivileged guest domains and ensure that the privcmd driver's domain-locking mode is manually activated from user land to limit hypercall targets. Prioritize patching on Xen-based systems running unprivileged guest domains with secure boot enabled (Feedly).
The vulnerability was disclosed via the oss-security mailing list shortly after publication, with multiple follow-up threads (oss-sec). Downstream vendors including SUSE, Debian, and Amazon Linux responded promptly with updated kernel packages. No notable independent researcher commentary or significant social media discussion beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."