Mapping Issues in an Open-Source Virtualization Product Affecting Multiple Domains
CVE-2025-58144
7.5HIGH
What is CVE-2025-58144?
This vulnerability arises from incorrect assertions related to the mapping of pages belonging to different domains within the Xen Hypervisor. Specifically, a NULL pointer dereference can occur in release builds due to mishandled assertions. Additionally, the failure to hold a P2M lock during the page reference acquisition process can lead to critical security risks, as the types and ownership of pages may be altered, resulting in potential violations of domain boundaries.
Affected Version(s)
Xen consult Xen advisory XSA-473
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Jan Beulich of SUSE.