https://seclists.org/oss-sec/2026/q3/671: Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation turn codes
Published Sep 8, 2026
·Updated
Affected Software
1 affected component
Xen Project Xen>=undefined
Frequently Asked Questions
1
Which deployments are exposed to this denial of service?
Only x86 Xen systems are vulnerable, and exploitation requires an unprivileged HVM guest with a passed-through PCI device that has at least one BAR in I/O port address space. Arm systems are not vulnerable.
2
What access does an attacker need?
An attacker needs control of an unprivileged HVM guest that has been assigned a qualifying PCI device. Such a guest can trigger a Xen BUG() and cause a denial of service affecting the entire host.
3
Are Xen installations affected by default?
The issue is only reachable where PCI passthrough to an unprivileged HVM guest includes a device with an I/O-space BAR. Systems without that assignment configuration cannot leverage the vulnerability through the described path.
4
What can be done if the patch cannot be applied immediately?
The advisory states that no mitigation is available. Applying the provided patch is the stated resolution.