PT-2026-95552 · Debian+1 · Xen
CVE-2026-79604
·
Published
2026-09-08
·
Updated
2026-09-08
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the global trie. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. All version of Xen from 4.6 onwards are vulnerable. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are not vulnerable.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xen