[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

There are multiple issues related to the handling and accessing of guest
memory pages in the viridian code:

1. A NULL pointer dereference in the updating of the reference TSC area.
This is CVE-2025-27466.

2. A NULL pointer dereference by assuming the SIM page is mapped when
a synthetic timer message has to be delivered. This is
CVE-2025-58142.

3. A race in the mapping of the reference TSC page, where a guest can
get Xen to free a page while still present in the guest physical to
machine (p2m) page tables. This is CVE-2025-58143.
Fixes

Solution

No solution given by the vendor.


Workaround

Not enabling the reference_tsc and stimer viridian extensions will avoid the issues.

History

Thu, 11 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-395
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Description [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.
Title Mutiple vulnerabilities in the Viridian interface
References

cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2025-09-11T14:40:33.401Z

Reserved: 2025-02-26T09:16:54.462Z

Link: CVE-2025-27466

cve-icon Vulnrichment

Updated: 2025-09-11T14:26:20.300Z

cve-icon NVD

Status : Received

Published: 2025-09-11T14:15:41.413

Modified: 2025-09-11T15:15:33.540

Link: CVE-2025-27466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.