CVE-2026-79603: Unconditionally do TLB flushing ahead of page scrubbing

Published Sep 8, 2026
·
Updated

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.

Event History

Sep 8, 2026
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

The issue affects x86 PV guests. The described exposure is tied to guest memory pages that are freed while a stale TLB entry still points to them.

2

What condition enables a guest to modify a scrubbed page?

A stale TLB entry must remain after the guest frees a page, and the page must be scrubbed before Xen performs any needed TLB flush. During that window, the PV guest can still use the stale mapping to modify the page.

3

Is page reuse required for Xen to issue the relevant TLB flush?

Yes. Xen issues a TLB flush, if needed, when the page is re-used. The vulnerability exists because scrubbing can occur before that reuse-triggered flush.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203