https://seclists.org/oss-sec/2026/q3/670: Xen Security Advisory 509 v3 (CVE-2026-62437) - x86: DMs may cause mem leak by IRQ binding

Published Sep 8, 2026
·
Updated

Affected Software

1 affected component
Xen Project Xen>=undefined

Frequently Asked Questions

1

Which guest configurations are exposed?

Only HVM guests with one or more assigned PCI devices can leverage the issue. Environments running only PV guests, or HVM guests without assigned PCI devices, are not exposed to exploitation through this condition.

2

What does an attacker need to do to trigger the leak?

The attacker needs control of an HVM guest with assigned PCI devices. During guest termination, the guest can cause its device model to bind IRQs again after earlier cleanup has occurred, leaving at least one tracking structure uncollected.

3

How can I identify systems that need attention?

Identify Xen hosts running HVM guests with PCI devices assigned to them. All Xen versions from at least 3.2 onward are affected; older versions were not inspected.

4

What is the consequence if the issue is exploited?

The issue leaks hypervisor memory. Repeated exploitation may exhaust host memory and cause denial of service affecting the entire host.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203