Логотип exploitDog
bind: "CVE-2025-58145"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-58145"

Количество 6

Количество 6

ubuntu логотип

CVE-2025-58145

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-58145

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-58145

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explai ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-j9v5-p5pj-rmp7

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-12598

около 2 месяцев назад

Уязвимость кроссплатформенного гипервизора Xen ядра операционной системы Linux, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250929-08

около 1 месяца назад

Множественные уязвимости xen

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-58145

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-58145

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-58145

[This CNA information record relates to multiple CVEs; the text explai ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-j9v5-p5pj-rmp7

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2025-12598

Уязвимость кроссплатформенного гипервизора Xen ядра операционной системы Linux, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20250929-08

Множественные уязвимости xen

CVSS3: 9.8
около 1 месяца назад

Уязвимостей на страницу