Mapping Issues in an Open-Source Virtualization Product Affecting Multiple Domains
CVE-2025-58144
7.5HIGH
What is CVE-2025-58144?
This vulnerability arises from incorrect assertions related to the mapping of pages belonging to different domains within the Xen Hypervisor. Specifically, a NULL pointer dereference can occur in release builds due to mishandled assertions. Additionally, the failure to hold a P2M lock during the page reference acquisition process can lead to critical security risks, as the types and ownership of pages may be altered, resulting in potential violations of domain boundaries.
Affected Version(s)
Xen consult Xen advisory XSA-473