https://seclists.org/oss-sec/2025/q4/70: Xen Security Advisory 476 v1 (CVE-2025-58149) - Incorct moval of permissions on PCI device unplug
Published Oct 24, 2025
·Updated
Affected Software
1 affected component
XEN Xen>=4.0
Frequently Asked Questions
1
What is the severity of CVE-2025-58149?
The severity of CVE-2025-58149 is considered high due to the potential for unauthorized access to PCI devices.
2
How do I fix CVE-2025-58149?
To fix CVE-2025-58149, update to the latest version of the Xen hypervisor where the vulnerability has been patched.
3
What is the impact of CVE-2025-58149 on Xen?
The impact of CVE-2025-58149 allows a malicious user to retain unauthorized access to PCI device memory after device unplug.
4
Which versions of Xen are affected by CVE-2025-58149?
CVE-2025-58149 affects multiple versions of the Xen hypervisor prior to the security patches released after October 24, 2025.
5
Is CVE-2025-58149 a local or remote vulnerability?
CVE-2025-58149 is considered a local vulnerability since it requires access to the system hosting the Xen hypervisor.