{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-62437","assignerOrgId":"23aa2041-22e1-471f-9209-9b7396fa234f","state":"PUBLISHED","assignerShortName":"XEN","dateReserved":"2026-07-14T10:28:12.655Z","datePublished":"2026-09-08T12:10:52.643Z","dateUpdated":"2026-09-10T18:13:23.073Z"},"containers":{"cna":{"title":"x86: DMs may cause mem leak by IRQ binding","datePublic":"2026-09-08T12:00:00.000Z","descriptions":[{"lang":"en","value":"When guests are terminated, various pieces of cleanup need carrying out.\nThe cleaning up of PCI devices which were assigned to guests, and the\nassociated removal of tracking structures for IRQs used by the devices\noccurs relatively early in the process.  Unfortunately after that point\nthe guest about to be terminated could cause its device model (DM) to\nre-establish such tracking structures, by having it bind one or more IRQs\nanew.  While some of those tracking structures would still be cleaned up\nlater on, at least one would not be."}],"impacts":[{"descriptions":[{"lang":"en","value":"A HVM guest with one or more PCI devices assigned can cause a memory leak\nin the hypervisor, possibly leading to Denial of Service (DoS) of the\nentire host."}]}],"affected":[{"defaultStatus":"unknown","product":"Xen","vendor":"Xen","versions":[{"status":"unknown","version":"consult Xen advisory XSA-509"}]}],"configurations":[{"lang":"en","value":"All Xen versions from at least 3.2 onwards are affected.  Older versions\nhave not been inspected.\n\nOnly HVM guests with assigned PCI devices can leverage the vulnerability."}],"workarounds":[{"lang":"en","value":"Running only PV or PVH guests will avoid the vulnerability.\n\nRunning only HVM guests without passing through PCI devices to them will\nalso avoid the vulnerability."}],"credits":[{"lang":"en","type":"finder","value":"This issue was discovered by Jan Beulich of SUSE."}],"references":[{"url":"https://xenbits.xenproject.org/xsa/advisory-509.html"}],"providerMetadata":{"orgId":"23aa2041-22e1-471f-9209-9b7396fa234f","shortName":"XEN","dateUpdated":"2026-09-08T12:10:52.643Z"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://xenbits.xen.org/xsa/advisory-509.html"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/08/6"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-08T17:08:26.757Z"}},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-362","lang":"en","description":"CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}]}],"metrics":[{"cvssV3_1":{"scope":"CHANGED","version":"3.1","baseScore":6.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-10T18:11:30.445915Z","id":"CVE-2026-62437","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-10T18:13:23.073Z"}}]}}