Description
x86 PV guests can free memory pages while still keeping a stale TLB entry
pointing to them. A TLB flush is only issued by Xen (if needed) when the
page is re-used. Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.
pointing to them. A TLB flush is only issued by Xen (if needed) when the
page is re-used. Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.
Published:
2026-09-08
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
There is no known mitigation.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-511.html |
|
History
Tue, 08 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page. | |
| Title | Unconditionally do TLB flushing ahead of page scrubbing | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2026-09-08T13:42:41.424Z
Reserved: 2026-08-25T07:35:05.289Z
Link: CVE-2026-79603
No data.
Status : Received
Published: 2026-09-08T13:17:27.253
Modified: 2026-09-08T13:17:27.253
Link: CVE-2026-79603
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.