[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

There are multiple issues related to the handling and accessing of guest
memory pages in the viridian code:

1. A NULL pointer dereference in the updating of the reference TSC area.
This is CVE-2025-27466.

2. A NULL pointer dereference by assuming the SIM page is mapped when
a synthetic timer message has to be delivered. This is
CVE-2025-58142.

3. A race in the mapping of the reference TSC page, where a guest can
get Xen to free a page while still present in the guest physical to
machine (p2m) page tables. This is CVE-2025-58143.
Fixes

Solution

No solution given by the vendor.


Workaround

Not enabling the reference_tsc and stimer viridian extensions will avoid the issues.

History

Thu, 11 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-366
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Description [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.
Title Mutiple vulnerabilities in the Viridian interface
References

cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2025-09-11T14:41:56.160Z

Reserved: 2025-08-26T06:48:41.443Z

Link: CVE-2025-58143

cve-icon Vulnrichment

Updated: 2025-09-11T14:23:28.802Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-11T14:15:42.470

Modified: 2025-09-11T17:14:10.147

Link: CVE-2025-58143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.