Back

HIGH

Use after free of paging structures in EPT

Published Mar 23, 2026

Description

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush.

Freeing of paging structures however is not deferred until the flushing is done, and can result in freed pages transiently being present in cached state. Such stale entries can point to memory ranges not owned by the guest, thus allowing access to unintended memory regions.

Affected products

Remediation

Vendor solution

There are no mitigations.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner XEN
Published Mar 23, 2026
Updated Mar 23, 2026
Reserved Jan 14, 2026
CISA Vulnrichment
Updated Mar 23, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner XEN
Published Mar 23, 2026
Updated Mar 23, 2026
Exploited since n/a
EUVD-2026-14382