[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are two issues related to the mapping of pages belonging to other
domains: For one, an assertion is wrong there, where the case actually
needs handling. A NULL pointer de-reference could result on a release
build. This is CVE-2025-58144.
And then the P2M lock isn't held until a page reference was actually
obtained (or the attempt to do so has failed). Otherwise the page can
not only change type, but even ownership in between, thus allowing
domain boundaries to be violated. This is CVE-2025-58145.
text explains which aspects/vulnerabilities correspond to which CVE.]
There are two issues related to the mapping of pages belonging to other
domains: For one, an assertion is wrong there, where the case actually
needs handling. A NULL pointer de-reference could result on a release
build. This is CVE-2025-58144.
And then the P2M lock isn't held until a page reference was actually
obtained (or the attempt to do so has failed). Otherwise the page can
not only change type, but even ownership in between, thus allowing
domain boundaries to be violated. This is CVE-2025-58145.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
There is no known mitigation.
References
Link | Providers |
---|---|
https://xenbits.xenproject.org/xsa/advisory-473.html |
![]() ![]() |
History
Thu, 11 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-362 | |
Metrics |
cvssV3_1
|
Thu, 11 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145. | |
Title | Arm issues with page refcounting | |
References |
|

Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2025-09-11T14:39:41.138Z
Reserved: 2025-08-26T06:48:41.443Z
Link: CVE-2025-58145

Updated: 2025-09-11T14:29:42.377Z

Status : Received
Published: 2025-09-11T14:15:42.737
Modified: 2025-09-11T15:15:36.890
Link: CVE-2025-58145

No data.

No data.