https://seclists.org/oss-sec/2026/q3/672: Xen Security Advisory 511 v3 (CVE-2026-79603) - Unconditionally do TLB flushing ahead of page scrubbing
Published Sep 8, 2026
·Updated
Affected Software
1 affected component
Xen Project Xen>=undefined
Deployments running Xen 4.13 or later with xsm=silo scrub-domheap configured are affected when x86 PV guests are present. The advisory states that this configuration does not prevent information exchange among guests in the presence of PV guests.
An attacker needs control of an x86 PV guest. The guest can free pages while retaining stale TLB entries and modify a page after it has been scrubbed but before the required TLB flush occurs.
No. Xen 4.12 and earlier do not have the scrub-domheap command-line option and are not vulnerable according to the advisory.
The advisory lists no known mitigation. Applying the appropriate attached patch is the stated resolution.