UBUNTU-CVE-2025-58144

Source
https://ubuntu.com/security/CVE-2025-58144
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-58144.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2025-58144
Upstream
Published
2025-09-11T14:15:00Z
Modified
2025-10-24T05:23:36Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL pointer de-reference could result on a release build. This is CVE-2025-58144. And then the P2M lock isn't held until a page reference was actually obtained (or the attempt to do so has failed). Otherwise the page can not only change type, but even ownership in between, thus allowing domain boundaries to be violated. This is CVE-2025-58145.

References

Affected packages

Ubuntu:16.04:LTS

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.6.5-0ubuntu1.4?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.5.1-0ubuntu1
4.5.1-0ubuntu2
4.6.0-1ubuntu1
4.6.0-1ubuntu2
4.6.0-1ubuntu4
4.6.0-1ubuntu4.1
4.6.0-1ubuntu4.2
4.6.0-1ubuntu4.3
4.6.5-0ubuntu1
4.6.5-0ubuntu1.1
4.6.5-0ubuntu1.2
4.6.5-0ubuntu1.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "libxen-4.6"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "libxenstore3.0"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.4-amd64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.4-arm64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.4-armhf"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.5-amd64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.5-arm64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.5-armhf"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.6-amd64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.6-arm64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-hypervisor-4.6-armhf"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-system-armhf"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-utils-4.6"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.6.5-0ubuntu1.4",
            "binary_name": "xenstore-utils"
        }
    ]
}

Ubuntu:18.04:LTS

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.9.2-0ubuntu1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.9.0-0ubuntu3
4.9.0-0ubuntu4
4.9.2-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "libxen-4.9"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "libxenstore3.0"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.6-amd64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.6-arm64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.6-armhf"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.7-amd64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.7-arm64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.7-armhf"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.8-amd64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.8-arm64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.8-armhf"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.9-amd64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.9-arm64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-hypervisor-4.9-armhf"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-system-armhf"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-utils-4.9"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.9.2-0ubuntu1",
            "binary_name": "xenstore-utils"
        }
    ]
}

Ubuntu:20.04:LTS

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.11.3+24-g14b62ab3e5-1ubuntu2.3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.9.2-0ubuntu2
4.9.2-0ubuntu6
4.9.2-0ubuntu7
4.11.3+24-g14b62ab3e5-1ubuntu1
4.11.3+24-g14b62ab3e5-1ubuntu2
4.11.3+24-g14b62ab3e5-1ubuntu2.2
4.11.3+24-g14b62ab3e5-1ubuntu2.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxencall1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxendevicemodel1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxenevtchn1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxenforeignmemory1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxengnttab1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxenmisc4.11"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxenstore3.0"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxentoolcore1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "libxentoollog1"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-4.11-amd64"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-4.11-arm64"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-4.11-armhf"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-4.9-amd64"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-4.9-arm64"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-4.9-armhf"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-hypervisor-common"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-system-armhf"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-utils-4.11"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.11.3+24-g14b62ab3e5-1ubuntu2.3",
            "binary_name": "xenstore-utils"
        }
    ]
}

Ubuntu:22.04:LTS

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.16.0-1~ubuntu2.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.11.4+24-gddaaccbbab-1ubuntu2
4.16.0-1~ubuntu2
4.16.0-1~ubuntu2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxencall1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxendevicemodel1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxenevtchn1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxenforeignmemory1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxengnttab1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxenhypfs1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxenmisc4.16"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxenstore4"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxentoolcore1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "libxentoollog1"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-hypervisor-4.16-amd64"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-hypervisor-4.16-arm64"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-hypervisor-4.16-armhf"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-hypervisor-common"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-system-armhf"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-utils-4.16"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.16.0-1~ubuntu2.1",
            "binary_name": "xenstore-utils"
        }
    ]
}

Ubuntu:24.04:LTS

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.17.3+10-g091466ba55-1.1ubuntu3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.17.2-1
4.17.2+55-g0b56bed864-1
4.17.2+76-ge1f9cb16e2-1
4.17.2+76-ge1f9cb16e2-1ubuntu1
4.17.3+10-g091466ba55-1
4.17.3+10-g091466ba55-1.1ubuntu2
4.17.3+10-g091466ba55-1.1ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxencall1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxendevicemodel1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxenevtchn1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxenforeignmemory1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxengnttab1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxenhypfs1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxenmisc4.17t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxenstore4t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxentoolcore1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "libxentoollog1t64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-hypervisor-4.17-amd64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-hypervisor-4.17-arm64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-hypervisor-4.17-armhf"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-hypervisor-common"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-system-armhf"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-utils-4.17"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.17.3+10-g091466ba55-1.1ubuntu3",
            "binary_name": "xenstore-utils"
        }
    ]
}

Ubuntu:25.04

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.20.0-1ubuntu1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.17.3+10-g091466ba55-1.1ubuntu3
4.19.1-1ubuntu3
4.20.0-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxencall1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxendevicemodel1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxenevtchn1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxenforeignmemory1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxengnttab1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxenhypfs1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxenmisc4.20"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxenstore4"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxentoolcore1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "libxentoollog1"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-hypervisor-4.20-amd64"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-hypervisor-4.20-arm64"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-hypervisor-common"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-utils-4.20"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.20.0-1ubuntu1",
            "binary_name": "xenstore-utils"
        }
    ]
}

Ubuntu:25.10

xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.20.0+68-g35cb38b222-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.20.0-1ubuntu1
4.20.0+68-g35cb38b222-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxen-dev"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxencall1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxendevicemodel1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxenevtchn1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxenforeignmemory1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxengnttab1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxenhypfs1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxenmisc4.20"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxenstore4"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxentoolcore1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "libxentoollog1"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-hypervisor-4.20-amd64"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-hypervisor-4.20-arm64"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-hypervisor-common"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-utils-4.20"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.20.0+68-g35cb38b222-1",
            "binary_name": "xenstore-utils"
        }
    ]
}