PT-2026-26014 · Intel+1 · Intel Ept+1
Roger Pau
·
Published
2026-01-01
·
Updated
2026-03-28
·
CVE-2026-23554
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Citrix XenServer version 8.4
Description
The Intel EPT paging code includes an optimization that defers flushing of cached EPT state until the p2m lock is released. However, the freeing of paging structures is not deferred, potentially leading to stale entries pointing to memory regions not owned by the guest. This can allow access to unintended memory regions. The issue may allow privileged code in a guest virtual machine to compromise the host system.
Recommendations
Update XenServer version 8.4 to the latest firmware or software.
Verify all XenServer 8.4 hosts are patched.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Xenserver 8.4
Intel Ept