Out-of-bounds write in Xen - CVE-2026-79606

 

Out-of-bounds write in Xen - CVE-2026-79606

Published: September 8, 2026


Vulnerability identifier: #VU147395
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-79606
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in gcopy_segs[] bounds checking when processing guest-supplied segment counts. A remote user can provide an nr_segments value between 12 and 32 to corrupt adjacent memory and execute arbitrary code.

The affected tapdisk process normally runs as root in dom0.


Affected software

Xen

How to mitigate CVE-2026-79606

Install security update from vendor's website.


External References

Related Security Bulletins