PT-2026-26014 · Intel+1 · Intel Ept+1
Roger Pau
·
Publicado
2026-01-01
·
Atualizado
2026-03-28
·
CVE-2026-23554
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Citrix XenServer version 8.4
Description
The Intel EPT paging code includes an optimization that defers flushing of cached EPT state until the p2m lock is released. However, the freeing of paging structures is not deferred, potentially leading to stale entries pointing to memory regions not owned by the guest. This can allow access to unintended memory regions. The issue may allow privileged code in a guest virtual machine to compromise the host system.
Recommendations
Update XenServer version 8.4 to the latest firmware or software.
Verify all XenServer 8.4 hosts are patched.
Correção
Time Of Check To Time Of Use
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citrix Xenserver 8.4
Intel Ept