Description
A guest started with Populated on Demand enabled (PoD) can attempt to
reclaim pages which aren't regular guest RAM. This can cause corruption
of memory management state in Xen.
Published: 2026-07-28
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a guest VM started with Populated on Demand (PoD) enabled to attempt to reclaim memory pages that do not belong to the guest’s allocated RAM. This action corrupts the Xen hypervisor’s memory‑management state, which can lead to hypervisor instability, crashes, or other unintended behavior. The weakness is a classic out‑of‑bounds write (CWE‑787).

Affected Systems

The Xen hypervisor is affected; no specific version exclusions are listed. All Xen installations that expose PoD‑enabled guests are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of <1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must control a PoD‑enabled guest to trigger the flaw, and no public exploit has been reported. Mitigation is achieved by disabling PoD or using PV or HVM/PVH guests without PoD.

Generated by OpenCVE AI on August 4, 2026 at 12:55 UTC.

Remediation

Vendor Workaround

Running only PV guests or HVM/PVH guests without PoD will avoid the vulnerability.


OpenCVE Recommended Actions

  • Run only PV or HVM/PVH guests without Populated on Demand to avoid the vulnerability.
  • Apply Xen patches that address PoD memory‑reclamation, and keep the hypervisor updated.
  • Audit guest configurations to ensure PoD is not enabled and enforce a policy that disallows PoD.

Generated by OpenCVE AI on August 4, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6424-1 xen security update
History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Xen
Xen xen
Vendors & Products Xen
Xen xen

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory management state in Xen.
Title PoD: Don't try to reclaim special pages
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2026-07-28T16:33:34.668Z

Reserved: 2026-07-14T10:28:12.655Z

Link: CVE-2026-62434

cve-icon Vulnrichment

Updated: 2026-07-28T16:33:34.668Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T13:19:02.317

Modified: 2026-07-28T17:16:58.200

Link: CVE-2026-62434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses