moksha-2026-0063

MEDIUM CVSS 5.3 moksha
Description

A vm-admin in XAPI-based hypervisors (XenServer, XCP-ng) can inject negative kbps values into VIF.qos_algorithm_params. XAPI parses via Int64.of_string without sign validation. xenopsd computes a negative bytes_per_interval which fails the >0L bounds check, silently dropping the rate limit. The XAPI database shows the negative value as the configured rate while no rate is enforced in xenstore, creating an observability gap for administrators and monitoring tools.

Timeline
Published
2026-04-24 06:00 UTC
Last Modified
2026-04-24
CVSS Details

CVSS details not available.

Affected Products
  • Cloud Software Group XenServer
  • Vates XCP-ng
Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "containers": {
    "cna": {
      "affected": [
        {
          "product": "XenServer",
          "vendor": "Cloud Software Group",
          "versions": [
            {
              "status": "affected",
              "version": "all",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "XCP-ng",
          "vendor": "Vates",
          "versions": [
            {
              "status": "affected",
              "version": "all",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Jakob Wolffhechel, Moksha"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vm-admin in XAPI-based hypervisors (XenServer, XCP-ng) can inject negative kbps values into VIF.qos_algorithm_params. XAPI parses via Int64.of_string without sign validation. xenopsd computes a negative bytes_per_interval which fails the >0L bounds check, silently dropping the rate limit. The XAPI database shows the negative value as the configured rate while no rate is enforced in xenstore, creating an observability gap for administrators and monitoring tools."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        },
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-20",
              "description": "Improper Input Validation",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-24T06:00:00Z",
        "orgId": "moksha.dk",
        "shortName": "Moksha"
      },
      "references": [
        {
          "url": "https://cna.moksha.dk/MOKSHA-2026-0063"
        }
      ],
      "title": "Negative kbps Injection in VIF.qos_algorithm_params"
    }
  },
  "cveMetadata": {
    "alternateIds": [
      "GCVE-117-2026-0063"
    ],
    "assignerOrgId": "moksha.dk",
    "cveId": "MOKSHA-2026-0063",
    "datePublished": "2026-04-24T06:00:00Z",
    "state": "PUBLISHED",
    "x_moksha_note": "Self-issued advisory. MOKSHA-2026-NNNN is not a MITRE CVE ID. Schema follows CVE JSON 5.1 for tooling compatibility. alternateIds contains GCVE cross-references (GNA #117) and will also carry MITRE CVE IDs if assigned."
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:id": "moksha-2026-0063",
  "vulnerability-lookup:score": 1777010400.0
}
View JSON API Download JSON