CVE-2026-79603

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 13:17

Updated : 2026-09-08 19:20


NVD link : CVE-2026-79603

Mitre link : CVE-2026-79603

CVE.ORG link : CVE-2026-79603


JSON object : View

Products Affected

No product.

CWE
CWE-664

Improper Control of a Resource Through its Lifetime