ZeroHour
Vendor

Xen Project

0 mentions in 7 days · 5 in 30 days · 5 total · first seen · last

Timeline

Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk

Xen published XSA-513 (CVE-2026-79605 and CVE-2026-79606): incorrect bounds checks in Tapdisk, the XAPI toolstack userspace xen-blkback, allow out-of-bounds accesses.

The Xen security team released XSA-513 version 3 as a public release, covering CVE-2026-79605 and CVE-2026-79606, out-of-bounds access flaws in Tapdisk. Tapdisk is the userspace xen-blkback implementation used by the XAPI toolstack. Several bounds checks were found to be incorrect, including a missing upper bounds check. The advisory was updated to version 3 for public release.

Xen Security Advisory 512 v3 (CVE-2026-79604) - oxenstored: Unbounded accumulation of watches

Xen Project released XSA-512 (CVE-2026-79604) fixing unbounded accumulation of watches in oxenstored that can exhaust resources after xenbus reconnects.

Xen Security Advisory 512 v3 publicly discloses CVE-2026-79604 in oxenstored, the OCaml xenstore implementation. Oxenstored maintains a global trie and per-domain hashtable for watches, and on a xenbus reconnect requests the watches are not cleared out of the global structure. This allows unbounded accumulation of watches. The Xen security team published the advisory and fix as a public release.

Xen Security Advisory 511 v3 (CVE-2026-79603) - Unconditionally do TLB flushing ahead of page scrubbing

Xen Project released XSA-511 (CVE-2026-79603) fixing missing TLB flushes before page scrubbing that can leak x86 PV guest data.

Xen Security Advisory 511 v3 publicly discloses CVE-2026-79603, a TLB handling flaw in the Xen hypervisor on x86. x86 PV guests can free memory pages while a stale TLB entry still points to them, and Xen only flushes the TLB when the page is reused, potentially exposing stale data ahead of scrubbing. The advisory changes Xen to unconditionally flush the TLB ahead of page scrubbing. The issue was published in version 3 of the advisory.

Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation return codes

Xen Project released XSA-510 (CVE-2026-79602) fixing mishandled HVM emulation return codes that let PCI-passthrough guests crash Xen.

Xen Security Advisory 510 v3 publicly discloses CVE-2026-79602, improper handling of HVM emulation return codes in the Xen hypervisor on x86. A guest with an assigned PCI device that has at least one BAR in the IO port space can trigger a BUG() in Xen. The advisory was released publicly as version 3.

Xen Security Advisory 509 v3 (CVE-2026-62437) - x86: DMs may cause mem leak by IRQ binding

Xen Project released XSA-509 (CVE-2026-62437) fixing a memory leak in IRQ tracking when guests with assigned PCI devices are terminated.

Xen Security Advisory 509 v3 publicly discloses CVE-2026-62437, a memory leak affecting the Xen hypervisor on x86. When guests are terminated, cleanup of PCI devices assigned to those guests and removal of associated IRQ tracking structures may fail, leaking memory. The advisory was released publicly as version 3.

oss-security · 7d agoVulnerabilityCVE-2026-62437

Related CVEs

  • Guest-triggerable hypervisor DoS in Xen via PCI passthrough I/O port BARs
    Xen's x86 hypervisor improperly handles return codes in its HVM instruction emulation path, and a guest that has been assigned a PCI device (via passthrough) whose BAR (Base Address Register) is mapped into the I/O port address space can trigger a BUG() in the hypervisor, as documented in Xen Security Advisory 510 (CVE-2026-79602). An attacker controlling such a guest — typically a guest administrator on a host using PCI device assignment — can deliberately trigger the flaw through guest actions that go through the emulation path. The outcome is a denial of service: the BUG() crashes the host's hypervisor, disrupting all guests on that physical machine; the advisory does not indicate privilege escalation or data exposure. Only x86 Xen deployments that assign PCI devices to guests where an assigned device has an I/O port BAR are affected; hosts without passthrough, or with MMIO-only devices, are not exposed. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% 30-day exploitation probability (7th percentile), so no exploitation is currently known.
    · Xen Project Xen hypervisor (x86) — HVM guests with PCI device assignment where the assigned device has a BAR in I/O port spacelarge
  • Memory leak in Xen hypervisor x86 IRQ tracking during guest teardown with PCI passthrough
    CVE-2026-62437 is a memory leak in the Xen hypervisor on x86 systems involving tracking structures for IRQs used by PCI devices assigned to guests. When a guest is terminated, cleanup of assigned PCI devices and their IRQ tracking normally happens early, but the guest's device model (DM) can re-establish that tracking by binding one or more IRQs anew after cleanup has run, and at least one of those re-created structures is never freed. An attacker who controls a guest with assigned PCI devices could repeatedly terminate guests (or trigger re-binding before termination) to steadily consume host memory, ultimately degrading or DoS-ing the host. Only Xen deployments on x86 that use PCI device passthrough with a device model are affected; operators not using passthrough are not exposed. There is no public proof-of-concept, the issue is not in CISA KEV, EPSS is 0.2% (7th percentile), and no exploitation is known.
    · Xen Project ([email protected] CNA) Xen hypervisor, x86 hosts using PCI device passthrough with a device modellarge
  • Stale TLB Entry Flaw in Xen Hypervisor Lets x86 PV Guests Modify Scrubbed Pages
    This is a memory-management flaw in the Xen hypervisor on x86 systems: a paravirtualized (PV) guest can free a memory page while a stale TLB (translation lookaside buffer) entry pointing to that page still exists, and Xen only issues a TLB flush, if needed, when the page is later re-used. Because the freed page can be scrubbed (zeroed) ahead of that deferred TLB flush, a window exists in which the guest can write to a page that has already been scrubbed, potentially corrupting or tainting memory Xen believes is clean. The practical impact, per the CVSS 3.1 score of 4.3 (medium, confidentiality impact only), is limited information exposure rather than privilege escalation or denial of service. Only operators of Xen hypervisors on x86 hardware that run PV guests are affected. Exploitation status is calm: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (14th percentile).
    · Xen Project Xen hypervisor (x86, with paravirtualized/PV guests) Affected version ranges are not specified in the available data; see Xen Security Advisory 511 v3 for the exact affected/patched version tablelarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.