Cross-Domain Vulnerability in Xen Project Products
CVE-2025-58145
7.5HIGH
What is CVE-2025-58145?
A security issue exists within the Xen Hypervisor that allows for cross-domain vulnerabilities due to inadequately handled P2M locks and incorrect assertion mappings. If the P2M lock is not held correctly until a page is referenced, it creates a risk of unauthorized access and potential ownership changes across domain boundaries. This flaw can lead to compromised security and unauthorized data exposure, necessitating immediate attention and remediation.
Affected Version(s)
Xen consult Xen advisory XSA-473