Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-58143

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2025
Última modificación:
11/09/2025

Descripción

*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> There are multiple issues related to the handling and accessing of guest<br /> memory pages in the viridian code:<br /> <br /> 1. A NULL pointer dereference in the updating of the reference TSC area.<br /> This is CVE-2025-27466.<br /> <br /> 2. A NULL pointer dereference by assuming the SIM page is mapped when<br /> a synthetic timer message has to be delivered. This is<br /> CVE-2025-58142.<br /> <br /> 3. A race in the mapping of the reference TSC page, where a guest can<br /> get Xen to free a page while still present in the guest physical to<br /> machine (p2m) page tables. This is CVE-2025-58143.

Referencias a soluciones, herramientas e información