https://seclists.org/oss-sec/2026/q3/674: Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdisk
Published Sep 8, 2026
·Updated
Affected Software
1 affected component
Xen Project Tapdisk=All versions
Frequently Asked Questions
1
Who can exploit these flaws, and what level of access do they need?
A malicious guest can exploit the flaws. The advisory identifies Tapdisk as a userspace xen-blkback implementation used by the XAPI toolstack.
2
What is the likely impact of successful exploitation?
Successful exploitation can give a malicious guest code execution in the tapdisk process running in dom0. Tapdisk normally runs as root.
3
Are any Tapdisk versions unaffected?
No. The advisory states that all versions of Tapdisk are vulnerable.
4
What can be done if patches cannot be applied immediately?
The advisory provides no mitigations. It states that applying the appropriate attached patches resolves the issues.