CVE-2025-58143
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2025
Last modified:
04/11/2025
Description
[This CNA information record relates to multiple CVEs; the<br />
text explains which aspects/vulnerabilities correspond to which CVE.]<br />
<br />
There are multiple issues related to the handling and accessing of guest<br />
memory pages in the viridian code:<br />
<br />
1. A NULL pointer dereference in the updating of the reference TSC area.<br />
This is CVE-2025-27466.<br />
<br />
2. A NULL pointer dereference by assuming the SIM page is mapped when<br />
a synthetic timer message has to be delivered. This is<br />
CVE-2025-58142.<br />
<br />
3. A race in the mapping of the reference TSC page, where a guest can<br />
get Xen to free a page while still present in the guest physical to<br />
machine (p2m) page tables. This is CVE-2025-58143.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* | 4.13.0 (including) | 4.17.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



