Memory Management Vulnerabilities in Xen Hypervisor
CVE-2025-27466
What is CVE-2025-27466?
Multiple vulnerabilities have been identified in the handling and accessing of guest memory pages in the Xen Hypervisor. One notable issue is a NULL pointer dereference that occurs during the update of the reference TSC area. Additionally, another vulnerability arises from incorrectly assuming that a SIM page is mapped when delivering a synthetic timer message. Furthermore, a race condition emerges in the mapping of the reference TSC page, allowing a guest to potentially free a page while it is still present in the guest's physical to machine (p2m) page tables. These issues could compromise system stability and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Xen consult Xen advisory XSA-472
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved