UBUNTU-CVE-2026-79603
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-79603
Summary:
Details: x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page. Deployments using `xsm=silo scrub-domheap` with the aim of not allowing the exchange of information amongst guests are not effective in the presence of PV guests. All Xen versions from 4.13 onwards are vulnerable. Xen versions 4.12 and earlier are not vulnerable as they lack the `scrub-domheap` command line option. Only x86 PV guests can exploit the vulnerability.
References: https://ubuntu.com/security/CVE-2026-79603, https://www.cve.org/CVERecord?id=CVE-2026-79603
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
