| Summary | In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is The first causes a buffer overflow as sprintf in buildid_show will 00000000 f4 91 51 f4 dd 38 9e 9d 65 47 52 eb 10 71 db 50 |..Q..8..eGR..q.P| So use a memcpy instead of sprintf to have the correct value: 00000000 f4 91 51 f4 dd 00 9e 9d 65 47 52 eb 10 71 db 50 |..Q.....eGR..q.P| (the above have a hack to embed a zero inside and check it's This is XSA-485 / CVE-2026-31786 |
|---|---|
| Publication Date | April 30, 2026, 8:16 p.m. |
| Registration Date | May 1, 2026, 4:07 a.m. |
| Last Update | May 1, 2026, 2:11 a.m. |