VSA-2026-036: Improper handling of HVM emulation return codes (CVE-2026-79602 / XSA-510)
| Published | Updated | Severity | CVSS 4.0 | Affected products |
|---|---|---|---|---|
| 2026-09-08 | 2026-09-08 | π Moderate | Not available yet | - XCP-ng 8.3 |
A vulnerability in the Xen hypervisor's handling of HVM emulation return codes has been discovered. For Vates products, we classify the impact as Moderate. For details on how we assign severity levels, see our Severity Levels Explained page.
Summaryβ
A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
Impactβ
Passing through a PCI device with at least one BAR in IO address space to unprivileged HVM guests can result in a Denial of Service (DoS) affecting the entire host.
Only HVM guests with a PCI device with IO BARs assigned can leverage the vulnerability.
Statusβ
- 2026-09-08: Released
Affected Versionsβ
- XCP-ng 8.3: Affected.
Mitigationβ
There is no mitigation available.
Resolutionβ
As of 2026-09-08, the updated xen-* packages for XCP-ng 8.3 have been updated to address this issue.
List of packages fixing this issue:
- XCP-ng 8.3:
xen-4.17.6-12.3.xcpng8.3
Creditsβ
This issue was discovered by Jiqian Chen of AMD and diagnosed as a security issue by Roger Pau MonnΓ© of AMD.