CVE-2026-62434: Xen
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory management state in Xen.
Affected products
- Xen Xen
Published 2026-07-28. Last modified 2026-07-28.