Impact
The vulnerability allows a guest VM started with Populated on Demand (PoD) enabled to attempt to reclaim memory pages that do not belong to the guest’s allocated RAM. This action corrupts the Xen hypervisor’s memory‑management state, which can lead to hypervisor instability, crashes, or other unintended behavior. The weakness is a classic out‑of‑bounds write (CWE‑787).
Affected Systems
The Xen hypervisor is affected; no specific version exclusions are listed. All Xen installations that expose PoD‑enabled guests are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of <1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must control a PoD‑enabled guest to trigger the flaw, and no public exploit has been reported. Mitigation is achieved by disabling PoD or using PV or HVM/PVH guests without PoD.
OpenCVE Enrichment
Debian DSA