Xen

3 known vulnerabilities in Xen, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-79603 CVSS 4.3 medium x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed)…
  • CVE-2026-79602 CVSS 8.8 high A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
  • CVE-2026-62437 CVSS 6.5 medium When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and…