{"schema_version":"1.7.5","id":"CVE-2025-58149","published":"2025-10-31T12:15:35.143Z","modified":"2026-04-16T04:32:59.173424950Z","related":["SUSE-SU-2025:4419-1","SUSE-SU-2025:4490-1","SUSE-SU-2026:0012-1","SUSE-SU-2026:0303-1","SUSE-SU-2026:0328-1","SUSE-SU-2026:0394-1","openSUSE-SU-2025:15719-1"],"details":"When passing through PCI devices, the detach logic in libxl won't remove\naccess permissions to any 64bit memory BARs the device might have.  As a\nresult a domain can still have access any 64bit memory BAR when such\ndevice is no longer assigned to the domain.\n\nFor PV domains the permission leak allows the domain itself to map the memory\nin the page-tables.  For HVM it would require a compromised device model or\nstubdomain to map the leaked memory into the HVM domain p2m.","affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58149.json","unresolved_ranges":[{"events":[{"introduced":"4.0.0"}]}]}}],"references":[{"type":"FIX","url":"https://xenbits.xenproject.org/xsa/advisory-476.html"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2025/10/24/1"},{"type":"FIX","url":"http://xenbits.xen.org/xsa/advisory-476.html"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}