2026-07-28 12:33CVE-2026-62434XEN
PUBLISHED5.2

PoD: Don't try to reclaim special pages

A guest started with Populated on Demand enabled (PoD) can attempt to

reclaim pages which aren't regular guest RAM. This can cause corruption

of memory management state in Xen.

Affected products

Xen

Xen

consult Xen advisory XSA-507 - UNKNOWN

References

GitHub Security Advisories

GHSA-q4cr-q8pj-wgf3

A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't...

https://github.com/advisories/GHSA-q4cr-q8pj-wgf3

A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory management state in Xen.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-62434
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-62434",
    "assignerOrgId": "23aa2041-22e1-471f-9209-9b7396fa234f",
    "assignerShortName": "XEN",
    "dateUpdated": "2026-07-28T13:34:16.161Z",
    "dateReserved": "2026-07-14T10:28:12.655Z",
    "datePublished": "2026-07-28T12:33:08.540Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "23aa2041-22e1-471f-9209-9b7396fa234f",
        "shortName": "XEN",
        "dateUpdated": "2026-07-28T12:33:08.540Z"
      },
      "datePublic": "2026-07-28T12:00:00.000Z",
      "title": "PoD: Don't try to reclaim special pages",
      "descriptions": [
        {
          "lang": "en",
          "value": "A guest started with Populated on Demand enabled (PoD) can attempt to\nreclaim pages which aren't regular guest RAM.  This can cause corruption\nof memory management state in Xen."
        }
      ],
      "affected": [
        {
          "vendor": "Xen",
          "product": "Xen",
          "defaultStatus": "unknown",
          "versions": [
            {
              "version": "consult Xen advisory XSA-507",
              "status": "unknown"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-507.html"
        }
      ],
      "impacts": [
        {
          "descriptions": [
            {
              "lang": "en",
              "value": "A buggy or malicious guest can cause corruption of Xen's state, leading\nto crashes or other malfunctions.  Information leak and privilege\nescalation cannot be ruled out."
            }
          ]
        }
      ],
      "configurations": [
        {
          "lang": "en",
          "value": "All Xen versions from 3.4 onwards are vulnerable.  Xen versions 3.3 and\nearlier are not vulnerable.\n\nOnly x86 systems are vulnerable.\n\nOnly x86 HVM and PVH guests started in populate-on-demand mode are\nbelieved to be able to leverage the vulnerability.  Populate-on-demand\nmode is activated when the guest's xl configuration file specifies a\n\"maxmem\" value which is larger than the \"memory\" value."
        }
      ],
      "workarounds": [
        {
          "lang": "en",
          "value": "Running only PV guests or HVM/PVH guests without PoD will avoid the\nvulnerability."
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE",
          "dateUpdated": "2026-07-28T13:34:16.161Z"
        },
        "title": "CVE Program Container",
        "references": [
          {
            "url": "http://xenbits.xen.org/xsa/advisory-507.html"
          }
        ]
      }
    ]
  }
}