HIGH
Use after free of paging structures in EPT
Published Mar 23, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush.
Freeing of paging structures however is not deferred until the flushing is done, and can result in freed pages transiently being present in cached state. Such stale entries can point to memory ranges not owned by the guest, thus allowing access to unintended memory regions.
Affected products
Remediation
Vendor solution
There are no mitigations.
Weaknesses (1)
References (4)
- http://www.openwall.com/lists/oss-security/2026/03/17/6 Mailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-480.html PatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14382 Advisory
- https://xenbits.xenproject.org/xsa/advisory-480.html PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/03/17/6 | Mailing ListPatchThird Party Advisory | |
| http://xenbits.xen.org/xsa/advisory-480.html | PatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14382 | Advisory | |
| https://xenbits.xenproject.org/xsa/advisory-480.html | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner XEN
Published Mar 23, 2026
Updated Mar 23, 2026
Reserved Jan 14, 2026
Link CVE-2026-23554
CISA Vulnrichment
Updated Mar 23, 2026
ENISA EUVD
EUVD-2026-14382 Assigner XEN
Published Mar 23, 2026
Updated Mar 23, 2026
Exploited since n/a
Link EUVD-2026-14382