VYPR
High severity7.5NVD Advisory· Published Sep 11, 2025· Updated Jun 17, 2026

CVE-2025-58145

CVE-2025-58145

Description

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]

There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144.

And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Xen/Xen2 versions
    cpe:2.3:o:xen:xen:*:*:*:*:*:*:arm:*+ 1 more
    • cpe:2.3:o:xen:xen:*:*:*:*:*:*:arm:*range: >=4.12.0,<4.17.0
    • (no CPE)range: consult Xen advisory XSA-473
  • Xen Project/Xenllm-fuzzy

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.