Security advisories (VSA)
All published Vates Security Advisories, one page per advisory with the impact, affected versions, mitigation and the packages fixing the issue. Search by VSA identifier, CVE or XSA number, or filter by severity, product and year; you can also browse by year in the sidebar.
48 advisories, showing 1-10
| Advisory | Published | Severity | Affected products | References |
|---|---|---|---|---|
| VSA-2026-039Out-of-bounds accesses in Tapdisk (CVE-2026-79605, CVE-2026-79606 / XSA-513) | 2026-09-08 | Critical | XCP-ng 8.3 | XSA-513, CVE-2026-79605, CVE-2026-79606 |
| VSA-2026-038Unbounded accumulation of watches in oxenstored (CVE-2026-79604 / XSA-512) | 2026-09-08 | Moderate | XCP-ng 8.3 | XSA-512, CVE-2026-79604 |
| VSA-2026-037Unconditionally do TLB flushing ahead of page scrubbing (CVE-2026-79603 / XSA-511) | 2026-09-08 | N/A | None | XSA-511, CVE-2026-79603 |
| VSA-2026-036Improper handling of HVM emulation return codes (CVE-2026-79602 / XSA-510) | 2026-09-08 | Moderate | XCP-ng 8.3 | XSA-510, CVE-2026-79602 |
| VSA-2026-035DMs may cause mem leak by IRQ binding (CVE-2026-62437 / XSA-509) | 2026-09-08 | Moderate | XCP-ng 8.3 | XSA-509, CVE-2026-62437 |
| VSA-2026-034PoD doesn't try to reclaim special pages (CVE-2026-62434 / XSA-507) | 2026-07-28 | Important | XCP-ng 8.3 | XSA-507, CVE-2026-62434 |
| VSA-2026-033incorrect buffer checks for DM_OP hypercalls (CVE-2026-62433 / XSA-506) | 2026-07-28updated 2026-09-08 | Low | XCP-ng 8.3 | XSA-506, CVE-2026-62433 |
| VSA-2026-032evtchn race between FIFO expand and reset (CVE-2026-62432 / XSA-505) | 2026-07-28 | Important | XCP-ng 8.3 | XSA-505, CVE-2026-62432 |
| VSA-2026-031Viridian STIMER division by zero (CVE-2026-62431 / XSA-504) | 2026-07-28 | Important | XCP-ng 8.3 | XSA-504, CVE-2026-62431 |
| VSA-2026-030out-of-bounds read in vRTC emulation (CVE-2026-62430 / XSA-503) | 2026-07-28 | Moderate | XCP-ng 8.3 | XSA-503, CVE-2026-62430 |
Page 1 of 5
Subscribe
Security teams can follow VSA publications without watching this page:
- RSS feed: /vsa/rss.xml
- Machine-readable index: /vsa/index.json, the same data that powers the list above, for scripts and vulnerability management tooling.
Was this page helpful?