CVE Database
/

CVE-2026-23554

Back to search

CVE-2026-23554

Published: Mar 23, 2026

Modified: Mar 23, 2026

PUBLISHED

Description

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging structures however is not deferred until the flushing is done, and can result in freed pages transiently being present in cached state. Such stale entries can point to memory ranges not owned by the guest, thus allowing access to unintended memory regions.

VendorProductVersions

Xen

Xen

unknown
consult Xen advisory XSA-480

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now