Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-79602
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-79602 is a Denial of Service vulnerability in the Xen hypervisor, tracked as Xen Security Advisory XSA-510, involving improper handling of HVM emulation return codes on x86 systems. A guest with a PCI device assigned that has at least one BAR (Base Address Register) on the IO port space can trigger a BUG() kernel assertion in Xen, crashing the hypervisor. Xen versions 4.6 and later are affected; ARM systems are not vulnerable. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Xen Advisory).

Technical details

The root cause is classified as CWE-617 (Reachable Assertion) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The vulnerability was introduced or exposed by the fix for XSA-491 and involves improper handling of HVM (Hardware Virtual Machine) emulation return codes when a PCI device with IO port space BARs is passed through to an unprivileged HVM guest. An attacker operating within such a guest can trigger the BUG() macro in Xen, causing a hypervisor crash. The issue was discovered by Jiqian Chen of AMD and diagnosed as a security issue by Roger Pau Monné of AMD (Openwall OSS-Sec, Red Hat Bugzilla).

Impact

Successful exploitation causes a Denial of Service affecting the entire Xen host, crashing the hypervisor and disrupting all virtual machines running on it. The CVSS scope is marked as "Changed," reflecting that the impact extends beyond the guest to the host and all co-located VMs, with high confidentiality, integrity, and availability impact ratings. Only x86 HVM guests with at least one PCI device with IO port space BARs assigned are capable of triggering this condition (Openwall OSS-Sec, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires low privileges (guest-level access) and no user interaction, but is not automatable due to the requirement for a specific hardware configuration (PCI device with IO port BAR assigned to the guest). The EPSS score is approximately 0.17%, indicating a low near-term exploitation probability. The CVE status is currently "Awaiting Analysis" and is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Gain guest access: Obtain or control an unprivileged HVM guest on a Xen x86 host running version 4.6 or later.
  2. Verify PCI device assignment: Confirm that the guest has a PCI device assigned with at least one BAR mapped to IO port address space (e.g., via lspci -v inside the guest or by reviewing the Xen configuration).
  3. Trigger HVM emulation path: Perform IO port access operations targeting the assigned PCI device's IO BAR from within the guest, causing Xen's HVM emulation layer to process the return codes.
  4. Trigger BUG(): The improper handling of HVM emulation return codes causes Xen to hit a BUG() assertion, crashing the hypervisor and causing a host-wide Denial of Service affecting all guests (Openwall OSS-Sec).

Indicators of compromise

  • Logs: Xen hypervisor crash logs or kernel panic messages referencing a BUG() assertion in HVM emulation code paths; unexpected host reboots or hypervisor restarts.
  • System Behavior: Sudden unavailability of all VMs on a Xen host; hypervisor watchdog timeouts or unexpected host resets.
  • Xen Console: Messages in the Xen serial/console log indicating assertion failures in IO port emulation or HVM handling routines around the time of the crash.

Mitigation and workarounds

The Xen Project has released patch xsa510.patch addressing this vulnerability, applicable to Xen 4.17.x and the unstable branch. Downstream distributions including SUSE (SUSE-SU-2026:4090-1) and others have issued updated packages. The Xen advisory states there is no configuration-based mitigation available; the only remediation is applying the patch. As an operational precaution, administrators should restrict PCI device passthrough with IO port space BARs to trusted HVM guests only until patched (Xen Advisory, Openwall OSS-Sec, SUSE Advisory).

Community reactions

The vulnerability was disclosed publicly via the Xen Project security team on the oss-security mailing list on September 8, 2026, following standard coordinated disclosure procedures. SUSE and openSUSE issued security updates promptly, and XCP-ng published a security update blog post for XCP-ng 8.3 LTS. Red Hat tracked the issue via Bugzilla but has not yet issued a patched package as of the last update (Openwall OSS-Sec, XCP-ng Blog, SUSE Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

xen

Affected

sid

xen

Affected

trixie

xen

Affected

Ubuntu

Unknown

bionic (esm-infra)

xen

Unknown

devel

xen

Unknown

focal (esm-apps)

xen

Unknown

jammy

xen

Unknown

jammy (esm-apps)

xen

Unknown

noble

xen

Unknown

noble (esm-apps)

xen

Unknown

resolute

xen

Unknown

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93574MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93562MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93894LOW2.3
  • Linux Debian logoLinux Debian
  • varnish
NoNoSep 18, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • perl
NoNoSep 19, 2026
CVE-2026-78030NONEN/A
  • Linux Debian logoLinux Debian
  • perl-DBI
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management