CVE-2026-62434

Summary

A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory management state in Xen.

Affected Software

VendorProductVersion RangeStatus
XenXenconsult Xen advisory XSA-507unknown

Weaknesses

Workarounds

Running only PV guests or HVM/PVH guests without PoD will avoid the vulnerability.

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References