CVE-2026-23553

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2026
Last modified:
28/01/2026

Description

In the context switch logic Xen attempts to skip an IBPB in the case of<br /> a vCPU returning to a CPU on which it was the previous vCPU to run.<br /> While safe for Xen&amp;#39;s isolation between vCPUs, this prevents the guest<br /> kernel correctly isolating between tasks. Consider:<br /> <br /> 1) vCPU runs on CPU A, running task 1.<br /> 2) vCPU moves to CPU B, idle gets scheduled on A. Xen skips IBPB.<br /> 3) On CPU B, guest kernel switches from task 1 to 2, issuing IBPB.<br /> 4) vCPU moves back to CPU A. Xen skips IBPB again.<br /> <br /> Now, task 2 is running on CPU A with task 1&amp;#39;s training still in the BTB.