https://seclists.org/oss-sec/2026/q3/674: Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk
Published Sep 8, 2026
·Updated
Affected Software
1 affected component
Xen Project Tapdisk=All versions
A malicious guest can exploit the flaws. The advisory identifies Tapdisk as a userspace xen-blkback implementation used by the XAPI toolstack.
Successful exploitation can give a malicious guest code execution in the tapdisk process running in dom0. Tapdisk normally runs as root.
No. The advisory states that all versions of Tapdisk are vulnerable.
The advisory provides no mitigations. It states that applying the appropriate attached patches resolves the issues.