ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 4 sources: “Xen publishes XSA-510 through XSA-513 (v3): four advisories covering hypervisor crashes, data exposure, oxenstored resource exhaustion, and Tapdisk out-of-bounds flaws” — merged summary and timeline →

Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk

AI summary · glm-5.3-flash

Xen published XSA-513 (CVE-2026-79605 and CVE-2026-79606): incorrect bounds checks in Tapdisk, the XAPI toolstack userspace xen-blkback, allow out-of-bounds accesses.

The Xen security team released XSA-513 version 3 as a public release, covering CVE-2026-79605 and CVE-2026-79606, out-of-bounds access flaws in Tapdisk. Tapdisk is the userspace xen-blkback implementation used by the XAPI toolstack. Several bounds checks were found to be incorrect, including a missing upper bounds check. The advisory was updated to version 3 for public release.

  • XSA-513 issued for two CVEs affecting Tapdisk
  • Tapdisk is the userspace xen-blkback implementation used by the XAPI toolstack
  • Multiple incorrect bounds checks identified, including a missing upper bounds check

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-79605

NVD description · AI analysis pending
CVE-2026-79606

NVD description · AI analysis pending
Full article

Posted by Xen . org security team on Sep 08 Xen Security Advisory CVE-2026-79605,CVE-2026-79606 / XSA-513 version 3 Out-of-bounds accesses in Tapdisk UPDATES IN VERSION 3 ==================== Public release. ISSUE DESCRIPTION ================= Tapdisk is a userspace xen-blkback implementation used by the XAPI toolstack. Several bounds checks have been found to be incorrect. * There is no upper bounds check for...

This source does not provide full text. Read it at seclists.org.