Логотип exploitDog
bind:"CVE-2025-58143"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-58143"

Количество 10

Количество 10

ubuntu логотип

CVE-2025-58143

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-58143

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-58143

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explai ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37qm-8w2q-wgx4

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2025-12596

около 2 месяцев назад

Уязвимость кроссплатформенного гипервизора Xen ядра операционной системы Linux, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю скомпрометировать уязвимую систему

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03172-1

около 2 месяцев назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3843-1

8 дней назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3798-1

9 дней назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3797-1

9 дней назад

Security update for xen

EPSS: Низкий
redos логотип

ROS-20250929-08

около 1 месяца назад

Множественные уязвимости xen

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-58143

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-58143

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-58143

[This CNA information record relates to multiple CVEs; the text explai ...

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-37qm-8w2q-wgx4

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2025-12596

Уязвимость кроссплатформенного гипервизора Xen ядра операционной системы Linux, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю скомпрометировать уязвимую систему

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03172-1

Security update for xen

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3843-1

Security update for xen

8 дней назад
suse-cvrf логотип
SUSE-SU-2025:3798-1

Security update for xen

9 дней назад
suse-cvrf логотип
SUSE-SU-2025:3797-1

Security update for xen

9 дней назад
redos логотип
ROS-20250929-08

Множественные уязвимости xen

CVSS3: 9.8
около 1 месяца назад

Уязвимостей на страницу