← Vulnerability feed

Vulnerability record · CVE-2026-23554 · published 23 March 2026

CVE-2026-23554: Xen toctou race condition vulnerability

Xen · Xen

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging structures however is not deferred until the flushing is done, and can result in freed pages transiently being present in cached state. Such stale entries can point to memory ranges not owned by the guest, thus allowing access to unintended memory regions.

7.8 CVSS 3.1 High EPSS 0.13% · top 97.9% CWE-367 · TOCTOU race condition
7.8CVSS 3.1 base score
0.13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging structures however is not deferred until the flushing is done, and can result in freed pages transiently being present in cached state. Such stale entries can point to memory ranges not owned by the guest, thus allowing access to unintended memory regions.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23554 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-10912Xen vulnerabilityXen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.EPSS 2.7%10.0CVE-2017-10918Xen improper input validation vulnerabilityXen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access…EPSS 3.7%10.0CVE-2017-10920Xen memory buffer overflow vulnerabilityThe grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unma…EPSS 2.5%10.0CVE-2017-10921Xen memory buffer overflow vulnerabilityThe grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows…EPSS 2.5%10.0CVE-2015-8104Xen vulnerabilityThe KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic o…EPSS 2.5%9.9CVE-2017-2620Qemu out-of-bounds write vulnerabilityQuick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could…EPSS 3.6%9.9CVE-2018-12892Debian linux information exposure vulnerabilityAn issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…EPSS 2.5%9.8CVE-2025-58142Xen vulnerability[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple i…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2026-23554), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.