Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: Xen Moderate Permission Issue CVE-2025-58149 Advisory 2025:4490-1

suse
Calendar Grey December 19, 2025
Dist Suse Esm H88
Update resolves security issue in Xen application for SUSE users, addressing permission removal flaws.
An update that solves one vulnerability and has two security fixes can now be installed.

Summary

## This update for xen fixes the following issues: Update to Xen 4.17.6. Security issues fixed: * CVE-2025-58149: incorrect removal of permissions on PCI device unplug allows PV guests to access memory of devices no longer assigned to them (bsc#1252692). Other issues fixed: * Several upstream bug fixes (bsc#1027519). * Failure to restart xenstored (bsc#1254180).

References

* bsc#1027519

* bsc#1252692

* bsc#1254180

Cross-

* CVE-2025-58149

CVSS scores:

* CVE-2025-58149 ( SUSE ): 4.3

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

* CVE-2025-58149 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

* CVE-2025-58149 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products:

* openSUSE Leap 15.5

* SUSE Linux Enterprise Micro 5.5

An update that solves one vulnerability and has two security fixes can now be

installed.

##

* https://www.suse.com/security/cve/CVE-2025-58149.html

* https://bugzilla.suse.com/show_bug.cgi?id=1027519

* https://bugzilla.suse.com/show_bug.cgi?id=1252692

* https://bugzilla.suse.com/show_bug.cgi?id=1254180

Announcement ID: SUSE-SU-2025:4490-1
Release Date: 2025-12-19T11:17:13Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here