https://seclists.org/oss-sec/2026/q3/673: Xen Security Advisory 512 v3 (CVE-2026-79604) - oxenstod: Unbounded accumulation of watches
Published Sep 8, 2026
·Updated
Affected Software
2 affected components
Xen Project Xen>=undefined
oxenstored (Ocaml Xenstored implementation)>=undefined
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Xen versions from 4.6 onward are affected only when they use the Ocaml Xenstored implementation (oxenstored). Deployments using the C Xenstored implementation are not vulnerable.
2
What must an attacker be able to do to trigger the denial of service?
A guest can trigger the issue by requesting xenbus reconnects, causing watches not to be removed from oxenstored's global trie. Repeated requests can produce unbounded memory consumption and a system-wide denial of service.
3
Is there a workaround if patches cannot be applied immediately?
No mitigations are provided. The stated resolution is to apply the appropriate attached patches.