CVE-2026-79603

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.

  • Published Sep 8, 2026
  • CVSS 4.3 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-79603 at the National Vulnerability Database