Memory Access Permission Vulnerability in Libxl for Xen Project
CVE-2025-58149
What is CVE-2025-58149?
This vulnerability arises from an oversight in the detach logic within Libxl, which fails to revoke access permissions for any 64-bit memory BARs when PCI devices are passed through. Consequently, a domain retains the ability to access these memory BARs even after the device has been detached. In the case of PV (paravirtualized) domains, the permission leak allows them to map the vulnerable memory directly in the page tables. For HVM (hardware virtual machine) domains, exploiting this leak necessitates a compromised device model or a stub domain to successfully map the leaked memory into the HVM domain’s physical-to-machine mapping.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Xen consult Xen advisory XSA-476
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved