
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-79602 is a Denial of Service vulnerability in the Xen hypervisor, tracked as Xen Security Advisory XSA-510, involving improper handling of HVM emulation return codes on x86 systems. A guest with a PCI device assigned that has at least one BAR (Base Address Register) on the IO port space can trigger a BUG() kernel assertion in Xen, crashing the hypervisor. Xen versions 4.6 and later are affected; ARM systems are not vulnerable. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Xen Advisory).
The root cause is classified as CWE-617 (Reachable Assertion) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The vulnerability was introduced or exposed by the fix for XSA-491 and involves improper handling of HVM (Hardware Virtual Machine) emulation return codes when a PCI device with IO port space BARs is passed through to an unprivileged HVM guest. An attacker operating within such a guest can trigger the BUG() macro in Xen, causing a hypervisor crash. The issue was discovered by Jiqian Chen of AMD and diagnosed as a security issue by Roger Pau Monné of AMD (Openwall OSS-Sec, Red Hat Bugzilla).
Successful exploitation causes a Denial of Service affecting the entire Xen host, crashing the hypervisor and disrupting all virtual machines running on it. The CVSS scope is marked as "Changed," reflecting that the impact extends beyond the guest to the host and all co-located VMs, with high confidentiality, integrity, and availability impact ratings. Only x86 HVM guests with at least one PCI device with IO port space BARs assigned are capable of triggering this condition (Openwall OSS-Sec, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires low privileges (guest-level access) and no user interaction, but is not automatable due to the requirement for a specific hardware configuration (PCI device with IO port BAR assigned to the guest). The EPSS score is approximately 0.17%, indicating a low near-term exploitation probability. The CVE status is currently "Awaiting Analysis" and is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).
lspci -v inside the guest or by reviewing the Xen configuration).BUG() assertion, crashing the hypervisor and causing a host-wide Denial of Service affecting all guests (Openwall OSS-Sec).BUG() assertion in HVM emulation code paths; unexpected host reboots or hypervisor restarts.The Xen Project has released patch xsa510.patch addressing this vulnerability, applicable to Xen 4.17.x and the unstable branch. Downstream distributions including SUSE (SUSE-SU-2026:4090-1) and others have issued updated packages. The Xen advisory states there is no configuration-based mitigation available; the only remediation is applying the patch. As an operational precaution, administrators should restrict PCI device passthrough with IO port space BARs to trusted HVM guests only until patched (Xen Advisory, Openwall OSS-Sec, SUSE Advisory).
The vulnerability was disclosed publicly via the Xen Project security team on the oss-security mailing list on September 8, 2026, following standard coordinated disclosure procedures. SUSE and openSUSE issued security updates promptly, and XCP-ng published a security update blog post for XCP-ng 8.3 LTS. Red Hat tracked the issue via Bugzilla but has not yet issued a patched package as of the last update (Openwall OSS-Sec, XCP-ng Blog, SUSE Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."