Impact
The disclosed flaw in the Xen hypervisor allows an x86 paravirtualized guest to free memory pages while a stale TLB entry still references them. Xen only issues a TLB flush when a page is reused, but the page may be scrubbed ahead of that flush, creating a race window. During this window a privileged PV guest can overwrite a scrubbed page, potentially corrupting memory that belongs to the hypervisor or other guests. This memory corruption can be leveraged by the attacker to gain unauthorized control of the hypervisor or another guest, or to cause a denial‑of‑service by destabilizing guest memory.
Affected Systems
All Xen hypervisor releases that employ the described TLB flush strategy for x86 paravirtualized guests are potentially vulnerable; no specific version numbers are identified in the advisory. The issue affects Xen and does not extend to other virtualization platforms such as KVM or hardware‑virtualization based guests.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, and no EPSS score is available. The race is exploitable only when an attacker has local privileged access within a PV guest, limiting the likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. If a privileged PV guest can race the page scrubbing and TLB flush, it could overwrite cleared memory, leading to privilege escalation or denial of service.
OpenCVE Enrichment