CVE-2026-79603 x86 PV guests can free memory pages while still… — CVE Notify — TG.ME

🚨 CVE-2026-79603
x86 PV guests can free memory pages while still keeping a stale TLB entry
pointing to them. A TLB flush is only issued by Xen (if needed) when the
page is re-used. Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.

🎖@cveNotify
👍1
September 8, 2026 54 1