September 2026 Security Updates #1 for XCP-ng 8.3 LTS
New security updates are available for XCP-ng 8.3 LTS.
Host reboots are necessary after this update.
đź“‹Summary
Security vulnerabilities have been detected and fixed in the xen hypervisor, oxenstored, and tapdisk. One of which is assessed as not impacting XCP-ng, and its fix will be added later as defence-in-depth.
We recommend updating as soon as your schedule permits.

đź”’Security Updates
Xen
XSA-509: DMs may cause a memory leak by IRQ binding: Termination of HVM guest with one or more PCI devices assigned could lead to a memory leak, in the worst case this can cause a Denial of Service of the entire host. Only HVM guests with assigned PCI devices can leverage this issue.
- References: VSA-2026-035, CVE-2026-62437, XSA-509
XSA-510: Improper handling of HVM emulation return codes: Passing a PCI device that has at least one BAR in the IO port space to an HVM guest can trigger a BUG() in Xen, leading to a Denial of Service affecting the entire host. Only HVM guests with a PCI device exposing an IO BAR assigned can leverage this issue.
- References: VSA-2026-036, CVE-2026-79602, XSA-510
oxenstored
XSA-512: Unbounded accumulation of watches: A guest could cause oxenstored to cause an unbounded memory usage. This can lead to a Denial of Service where guests keep running but are no longer configurable or manageable.
- References: VSA-2026-038, CVE-2026-79604, XSA-512
Tapdisk
XSA-513: Out-of-bounds accesses in Tapdisk: Several bounds checks issues were found in tapdisk. These could allow a malicious guest to obtain code execution within the tapdisk process running as root in dom0 granting it administrator privileges on the dom0 (control domain).
- References: VSA-2026-039, XSA-513
Not Fixed in this release
Xen
XSA-511: Unconditionally do TLB flushing ahead of page scrubbing: Only relates to non-supported PV guests, XCP-ng 8.3 LTS is deemed not impacted, the fix will be still be integrated at a later time in order to stay aligned with upstream.
- References: VSA-2026-037, CVE-2026-79603, XSA-511