UBUNTU-CVE-2026-79604
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-79604
Summary:
Details: oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the global trie. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. All version of Xen from 4.6 onwards are vulnerable. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are not vulnerable.
References: https://ubuntu.com/security/CVE-2026-79604, https://www.cve.org/CVERecord?id=CVE-2026-79604
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
