VSA-2026-031: Viridian STIMER division by zero (CVE-2026-62431 / XSA-504)
| Published | Updated | Severity | CVSS 4.0 | Affected products |
|---|---|---|---|---|
| 2026-07-28 | 2026-07-28 | 🔴 Important | Not available yet | - XCP-ng 8.3 |
A division by zero vulnerability in the Xen hypervisor's Viridian STIMER implementation has been discovered. For Vates products, we classify the impact as Important, as enabling Viridian STIMERs can result in a Denial of Service affecting the entire host. For details on how we assign severity levels, see our Severity Levels Explained page.
Summary​
The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.
Impact​
Enabling Viridian STIMERs for unprivileged HVM guests can result in a Denial of Service (DoS) affecting the entire host.
Affected Versions​
- XCP-ng 8.3: Affected, only HVM guests with Viridian STIMERs enabled.
Mitigation​
Not enabling Viridian STIMERs for HVM guests will avoid the vulnerability. Note that Viridian extensions might be enabled by default for Windows VMs depending of the template used at creation/import.
Resolution​
As of 2026-07-28, the updated xen-* packages for XCP-ng 8.3 have been updated to address this issue.
List of packages fixing this issue:
- XCP-ng 8.3:
4.17.6-9.3.1.xcpng8.3