Memory Access Vulnerability in Intel Virtualization Products
CVE-2026-23554

7.8HIGH

Key Information:

Vendor
CVE Published:
23 March 2026

What is CVE-2026-23554?

The Intel EPT paging code features an optimization to minimize performance impact by deferring the flushing of cached EPT states until the p2m lock is released. However, this optimization does not account for the immediate freeing of paging structures, leading to possible retention of stale entries in the cache. These entries could reference memory ranges outside of the guest's control, enabling potential unauthorized access to sensitive memory areas. This flaw presents a security risk in virtualized environments where proper memory isolation is crucial.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Xen consult Xen advisory XSA-480

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Roger Pau Monné of XenServer.
.