UBUNTU-CVE-2026-79602
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-79602
Summary:
Details: improper handling of HVM emulation return codes: A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. Xen versions 4.6 and later are vulnerable. This is known to be the case with the fix for XSA-491, but it's possible the issue can also be triggered from other, non-analyzed paths. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only HVM guests with a PCI device with IO BARs assigned can leverage the vulnerability.
References: https://ubuntu.com/security/CVE-2026-79602, https://www.cve.org/CVERecord?id=CVE-2026-79602
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
