Ad

CVE-2025-58149

HIGH CVSS 3.1: 7.5 EPSS 0.06%
Updated Jan 14, 2026
Xen
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions from 4.0.0
Type CWE-672
Vendor Xen
Public PoC No

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assigned to the domain. For PV domains the permission leak allows the domain itself to map the memory in the page-tables.

For HVM it would require a compromised device model or stubdomain to map the leaked memory into the HVM domain p2m.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Xen Xen
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
4.0.0