Mapping Issues in an Open-Source Virtualization Product Affecting Multiple Domains
CVE-2025-58144

7.5HIGH

Key Information:

Vendor
CVE Published:
11 September 2025

What is CVE-2025-58144?

This vulnerability arises from incorrect assertions related to the mapping of pages belonging to different domains within the Xen Hypervisor. Specifically, a NULL pointer dereference can occur in release builds due to mishandled assertions. Additionally, the failure to hold a P2M lock during the page reference acquisition process can lead to critical security risks, as the types and ownership of pages may be altered, resulting in potential violations of domain boundaries.

Affected Version(s)

Xen consult Xen advisory XSA-473

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Jan Beulich of SUSE.
.
CVE-2025-58144 : Mapping Issues in an Open-Source Virtualization Product Affecting Multiple Domains