Out-of-bounds write in Xen - CVE-2026-79606
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in gcopy_segs[] bounds checking when processing guest-supplied segment counts. A remote user can provide an nr_segments value between 12 and 32 to corrupt adjacent memory and execute arbitrary code.
The affected tapdisk process normally runs as root in dom0.