Resource exhaustion in Xen - CVE-2026-79604
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in oxenstored when handling xenbus reconnect requests. A local user can repeatedly request xenbus reconnects to cause a denial of service.
Only systems using the Ocaml Xenstored implementation are affected.