Permissions, Privileges, and Access Controls in Xen - CVE-2025-58149

 

Permissions, Privileges, and Access Controls in Xen - CVE-2025-58149

Published: October 24, 2025


Vulnerability identifier: #VU117653
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58149
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious guest to access sensitive information. 

The vulnerability exists due to PCI detach logic in libxl that does not remove access permissions to any 64bit memory BARs the device might have. A malicious guest can access any 64bit memory BAR when such device is no longer assigned to the domain.


Affected software

Xen
SUSE Linux Enterprise Server 15 SP6
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Server Applications Module
Basesystem Module
openSUSE Leap
Fedora
xen-doc-html
xen-tools-debuginfo
xen-tools-domU-debuginfo
xen-tools
xen-debugsource
xen-libs
xen-libs-32bit
xen
xen-libs-debuginfo-32bit
xen-tools-domU
xen-libs-debuginfo
xen-devel
xen-libs-64bit-debuginfo
xen-libs-64bit
xen-libs-32bit-debuginfo
xen-tools-xendomains-wait-disk
xen (Debian package)

How to mitigate CVE-2025-58149

Install updates from vendor's website.

xen-doc-html - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2
xen-tools-debuginfo - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-tools-domU-debuginfo - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-tools - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-debugsource - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-libs - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-libs-32bit - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2
xen - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-libs-debuginfo-32bit - update to 4.12.4_64-3.137.1
xen-tools-domU - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-libs-debuginfo - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-devel - addressed in versions 4.12.4_64-3.137.1, 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen-libs-64bit-debuginfo - addressed in versions 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2
xen-libs-64bit - addressed in versions 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2
xen-libs-32bit-debuginfo - addressed in versions 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2
xen-tools-xendomains-wait-disk - addressed in versions 4.14.6_28-150300.3.94.1, 4.16.7_06-150400.4.78.1, 4.17.6_02-150500.3.56.1, 4.18.5_08-150600.3.34.2, 4.20.2_02-150700.3.19.1
xen (Debian package) - addressed in versions 4.17.5+72-g01140da4e8-1, 4.20.2+7-g1badcf5035-0+deb13u1
xen - addressed in versions 4.19.3-7.fc41, 4.19.3-8.fc42, 4.20.1-8.fc43

External References

Related Security Bulletins