Race condition in Xen - CVE-2026-79603

 

Race condition in Xen - CVE-2026-79603

Published: September 8, 2026


Vulnerability identifier: #VU147397
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-79603
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass intended isolation between guests.

The vulnerability exists due to a race condition between TLB flushing and page scrubbing in Xen\'s x86 PV guest memory management when freeing memory pages while retaining stale TLB entries. A local user can free a memory page while retaining a stale TLB entry to bypass intended isolation between guests.

Only x86 PV guests are affected, and exploitation is relevant when xsm=silo scrub-domheap is configured.


Affected software

Xen
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Basesystem Module
Server Applications Module
openSUSE Leap
xen-tools-xendomains-wait-disk
xen-libs
xen-devel
xen-libs-debuginfo
xen-tools-domU-debuginfo
xen-tools-domU
xen-debugsource
xen-doc-html
xen
xen-libs-32bit-debuginfo
xen-tools
xen-tools-debuginfo
xen-libs-32bit

How to mitigate CVE-2026-79603

Install security update from vendor's website.

xen-tools-xendomains-wait-disk - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-libs - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-devel - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-libs-debuginfo - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-tools-domU-debuginfo - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-tools-domU - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-debugsource - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-doc-html - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1
xen - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-libs-32bit-debuginfo - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1
xen-tools - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-tools-debuginfo - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1, 4.20.4_04-150700.3.46.1
xen-libs-32bit - addressed in versions 4.16.7_14-150400.4.92.1, 4.17.6_16-150500.3.79.1

External References

Related Security Bulletins