MEDIUM 4.3 NVD
CVE-2026-79603
x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-u
x86 PV guests can free memory pages while still keeping a stale TLB entry
pointing to them. A TLB flush is only issued by Xen (if needed) when the
page is re-used. Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.
References
- https://xenbits.xenproject.org/xsa/advisory-511.html
- http://www.openwall.com/lists/oss-security/2026/09/08/8
- http://xenbits.xen.org/xsa/advisory-511.html
- https://www.openwall.com/lists/oss-security/2026/09/08/8
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.