Description
A guest with a PCI device assigned that has at least a BAR on the IO port
space can trigger a BUG() in Xen.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service – hypervisor crash
Action: Monitor
AI Analysis

Impact

A guest can trigger a BUG() in the Xen hypervisor when it is assigned a PCI device that has at least one Base Address Register on the I/O port space. The improper handling of HVM emulation return codes causes the hypervisor to panic, leading to a system-wide denial of service. The failure to validate the return status is a logic flaw that can be exploited by a guest with the appropriate PCI configuration.

Affected Systems

Xen hypervisor is affected. No specific version information is supplied, so any Xen installation that allows guests to own PCI devices with I/O BARs should be reviewed for the presence of this issue.

Risk and Exploitability

With a CVSS score of 8.8 and severity is high but the likelihood of exploitation remains low. The entry is not listed in CISA KEV, indicating no known active exploitation yet. The likely attack vector is that a guest owning a PCI device with an I/O BAR must be able to make an HVM call; the attack is thus internal to the hypervisor environment and does not require an external network connection. Exploitation conditions therefore involve the configuration of the guest and the hypervisor's PCI mapping. The bug can be triggered by generating a specific HVM state transition that relies on the incorrect handling of the return a loss of service for all guests on that host.

Generated by OpenCVE AI on September 11, 2026 at 07:30 UTC.

Remediation

Vendor Workaround

There is no mitigation available.


OpenCVE Recommended Actions

  • Validate the PCI configuration of guests and restrict or remove I/O BARs from devices that are assigned to Xen VMs until a vendor update is available.
  • Upgrade to the latest Xen release that includes the fix or review the vendor’s release notes for any mitigating changes.
  • Monitor hypervisor logs and event streams for BUG() messages or kernel panics and configure alerts so that incidents can be detected promptly.

Generated by OpenCVE AI on September 11, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-252

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Xen
Xen xen
Vendors & Products Xen
Xen xen

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-252

Tue, 08 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
Title x86: improper handling of HVM emulation return codes
References

cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2026-09-10T18:08:59.554Z

Reserved: 2026-08-25T07:35:05.289Z

Link: CVE-2026-79602

cve-icon Vulnrichment

Updated: 2026-09-08T17:08:32.715Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T13:17:27.157

Modified: 2026-09-10T19:17:34.963

Link: CVE-2026-79602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:45:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer