Description
When guests are terminated, various pieces of cleanup need carrying out.
The cleaning up of PCI devices which were assigned to guests, and the
associated removal of tracking structures for IRQs used by the devices
occurs relatively early in the process. Unfortunately after that point
the guest about to be terminated could cause its device model (DM) to
re-establish such tracking structures, by having it bind one or more IRQs
anew. While some of those tracking structures would still be cleaned up
later on, at least one would not be.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak during Guest Termination
Action: Apply Workaround
AI Analysis

Impact

The vulnerability arises when a Xen hypervisor cleans up PCI devices and associated IRQ tracking structures for a terminating guest. The device model (DM) can re-bind these IRQs shortly after the cleanup, causing some tracking structures to remain unreleased., potentially destabilizing the host. This race condition is identified as CWE‑362.

Affected Systems

is released by the Xen project. The issue applies to any guest that uses device models.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is less than 1%, suggesting a low exploitation probability, and the vulnerability is not listed in CISA KEV. The memory leak could lead to resource exhaustion if repeatedly triggered by repeated guest terminations, potentially destabilizing the host.

Generated by OpenCVE AI on September 11, 2026 at 08:26 UTC.

Remediation

Vendor Workaround

Running only PV or PVH guests will avoid the vulnerability. Running only HVM guests without passing through PCI devices to them will also avoid the vulnerability.


OpenCVE Recommended Actions

  • Run only PV or PVH guests and avoid launching HVM guests that receive PCI passthrough
  • Disable or remove PCI passthrough in any HVM guest configuration to eliminate the IRQ re‑binding path
  • Check Xen project advisories for a subsequent patch that fixes the cleanup logic and apply the upgrade when it becomes available

Generated by OpenCVE AI on September 11, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-391

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Xen
Xen xen
Vendors & Products Xen
Xen xen

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-391

Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that point the guest about to be terminated could cause its device model (DM) to re-establish such tracking structures, by having it bind one or more IRQs anew. While some of those tracking structures would still be cleaned up later on, at least one would not be.
Title x86: DMs may cause mem leak by IRQ binding
References

cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2026-09-10T18:13:23.073Z

Reserved: 2026-07-14T10:28:12.655Z

Link: CVE-2026-62437

cve-icon Vulnrichment

Updated: 2026-09-08T17:08:26.757Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T13:17:19.623

Modified: 2026-09-10T19:17:31.640

Link: CVE-2026-62437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')