SB2026090870 - SUSE update for xen
Published: September 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Memory leak (CVE-ID: CVE-2026-62437)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper cleanup of IRQ tracking structures in Xen\'s PCI device and IRQ cleanup handling when an HVM guest with assigned PCI devices is being terminated. A local user can cause the device model to bind IRQs anew during guest termination to cause a denial of service.
2) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-79602)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of HVM emulation return codes in Xen HVM emulation when processing a guest with an assigned PCI device containing an I/O BAR. A local user can trigger a BUG() in Xen to cause a denial of service.
Only x86 systems are affected.
3) Race condition (CVE-ID: CVE-2026-79603)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass intended isolation between guests.
The vulnerability exists due to a race condition between TLB flushing and page scrubbing in Xen\'s x86 PV guest memory management when freeing memory pages while retaining stale TLB entries. A local user can free a memory page while retaining a stale TLB entry to bypass intended isolation between guests.
Only x86 PV guests are affected, and exploitation is relevant when xsm=silo scrub-domheap is configured.
Remediation
Install update from vendor's website.