PT-2026-26014 · Intel+1 · Intel Ept+1

Roger Pau

·

Publicado

2026-01-01

·

Atualizado

2026-03-28

·

CVE-2026-23554

CVSS v3.1

7.8

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix XenServer version 8.4
Description The Intel EPT paging code includes an optimization that defers flushing of cached EPT state until the p2m lock is released. However, the freeing of paging structures is not deferred, potentially leading to stale entries pointing to memory regions not owned by the guest. This can allow access to unintended memory regions. The issue may allow privileged code in a guest virtual machine to compromise the host system.
Recommendations Update XenServer version 8.4 to the latest firmware or software. Verify all XenServer 8.4 hosts are patched.

Correção

Time Of Check To Time Of Use

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23554
MGASA-2026-0068
OPENSUSE-SU-2026:10457-1
SUSE-SU-2026:0908-1
SUSE-SU-2026:1092-1
SUSE-SU-2026:1093-1

Produtos afetados

Citrix Xenserver 8.4
Intel Ept