https://seclists.org/oss-sec/2026/q1/119: Xen Security Advisory 479 v2 (CVE-2026-23553) - x86: incomplete IBPB for vCPU isolation
Published Jan 27, 2026
·Updated
Affected Software
1 affected component
Xen Project Xen>=4.6
Affected systems are x86 Xen deployments with the XSA-254 fixes backported. Upstream Xen 4.6 and newer are vulnerable; Arm systems are not vulnerable.
The issue involves a vCPU moving between physical CPUs while the guest switches tasks. Xen can skip IBPB when the vCPU returns to a CPU it previously ran on, leaving branch-target-buffer training from an earlier guest task available while a different task runs.
Guest processes may use information leaks to obtain information intended to remain private to other entities in the same guest.