๐Ÿ” CVE Alert

CVE-2026-62437

MEDIUM 6.5

x86: DMs may cause mem leak by IRQ binding

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that point the guest about to be terminated could cause its device model (DM) to re-establish such tracking structures, by having it bind one or more IRQs anew. While some of those tracking structures would still be cleaned up later on, at least one would not be.

Vendor xen
Product xen
Published Sep 8, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for xen xen

Be the first to know when new medium vulnerabilities affecting xen xen are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Xen / Xen
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
xenbits.xenproject.org: https://xenbits.xenproject.org/xsa/advisory-509.html xenbits.xen.org: http://xenbits.xen.org/xsa/advisory-509.html openwall.com: http://www.openwall.com/lists/oss-security/2026/09/08/6

Credits

This issue was discovered by Jan Beulich of SUSE.