Skip to main content

VSA-2026-034: PoD doesn't try to reclaim special pages (CVE-2026-62434 / XSA-507)

PublishedUpdatedSeverityCVSS 4.0Affected products
2026-07-282026-07-28🔴 ImportantNot available yet- XCP-ng 8.3
info

A vulnerability in the Xen hypervisor's Populate on Demand (PoD) feature has been discovered. For Vates products, we classify the impact as Important, as a buggy or malicious guest can cause corruption of Xen's state leading to crashes or other malfunctions. For details on how we assign severity levels, see our Severity Levels Explained page.

Summary​

A guest started with Populate on Demand (PoD) enabled can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory management state in Xen.

Populate-on-demand mode is activated when the guest's configuration specifies a "maxmem" value which is larger than the "memory" value.

Impact​

A buggy or malicious guest can cause corruption of Xen's state, leading to crashes or other malfunctions. Information leak and privilege escalation cannot be ruled out.

Affected Versions​

  • XCP-ng 8.3: Affected, only x86 HVM and PVH guests started in populate-on-demand mode.

Mitigation​

Running only PV guests or HVM/PVH guests without PoD will avoid the vulnerability. You can check the parameters in Xen Orchestra 5, under the Advanced tab of a VM in the "VM limits" section, and ensure the three configurable memory values are identical. Note: this setup needs to be present at VM boot for PoD to be fully disabled.

Resolution​

As of 2026-07-28, the updated xen-* packages for XCP-ng 8.3 have been updated to address this issue.

List of packages fixing this issue:

  • XCP-ng 8.3:
    • 4.17.6-9.3.1.xcpng8.3

References​