4.3

CVE-2026-79603

Unconditionally do TLB flushing ahead of page scrubbing

x86 PV guests can free memory pages while still keeping a stale TLB entry
pointing to them.  A TLB flush is only issued by Xen (if needed) when the
page is re-used.  Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerXen
≫
Produkt Xen
Default Statusunknown
Version consult Xen advisory XSA-511
Status unknown
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.139
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-664 Improper Control of a Resource Through its Lifetime

The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

https://xenbits.xenproject.org/xsa/advisory-511.html
http://xenbits.xen.org/xsa/advisory-511.html
http://www.openwall.com/lists/oss-security/2026/09/08/8