UBUNTU-CVE-2026-79604

    Dashboard / Vulnerabilities / UBUNTU-CVE-2026-79604

    UBUNTU-CVE-2026-79604

    Published: 8 Sept 2026Last Modified: 9 Sept 2026
    Upstream:

    Summary:

    Details: oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the global trie. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. All version of Xen from 4.6 onwards are vulnerable. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are not vulnerable.

    Affected packages

    Package

    Name: xen

    Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    4.5.1-0ubuntu1
    4.5.1-0ubuntu2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2026-79604 | CVE-DB