https://seclists.org/oss-sec/2026/q3/671: Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation turn codes
Published Sep 8, 2026
·Updated
Affected Software
1 affected component
Xen Project Xen>=undefined
Only x86 Xen systems are vulnerable, and exploitation requires an unprivileged HVM guest with a passed-through PCI device that has at least one BAR in I/O port address space. Arm systems are not vulnerable.
An attacker needs control of an unprivileged HVM guest that has been assigned a qualifying PCI device. Such a guest can trigger a Xen BUG() and cause a denial of service affecting the entire host.
The issue is only reachable where PCI passthrough to an unprivileged HVM guest includes a device with an I/O-space BAR. Systems without that assignment configuration cannot leverage the vulnerability through the described path.
The advisory states that no mitigation is available. Applying the provided patch is the stated resolution.