CVE-2026-79602
Publication date 8 September 2026
Last updated 9 September 2026
Ubuntu priority
Description
improper handling of HVM emulation return codes: A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. Xen versions 4.6 and later are vulnerable. This is known to be the case with the fix for XSA-491, but it's possible the issue can also be triggered from other, non-analyzed paths. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only HVM guests with a PCI device with IO BARs assigned can leverage the vulnerability.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| xen | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Notes
mdeslaur
hypervisor packages are in universe. For issues in the hypervisor, add appropriate tags to each section, ex: Tags_xen: universe-binary