CVE-2025-58150

HIGH EPSS 2.8%
Published Jan 28, 20265mo ago · Modified Jun 17, 20262w ago
8.8 CVSS 3.1
High
Find Similar
Published Jan 28, 2026 5mo ago
Last Modified Jun 17, 2026 2w ago

Description

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.

CVSS Details

Base Score
8.8
Exploitability
2.0
Impact
6.0
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
2.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 1

VendorProductVersionRange
xenxen*any

References 3

  • openwall.com http://www.openwall.com/lists/oss-security/2026/01/27/1
    Mailing ListMitigationPatchThird Party Advisory
  • xenbits.xen.org http://xenbits.xen.org/xsa/advisory-477.html
    Mailing ListPatchVendor Advisory
  • xenbits.xenproject.org https://xenbits.xenproject.org/xsa/advisory-477.html
    MitigationPatchVendor Advisory

Remediation

  • openwall.com http://www.openwall.com/lists/oss-security/2026/01/27/1
    Mailing ListMitigationPatchThird Party Advisory
  • xenbits.xen.org http://xenbits.xen.org/xsa/advisory-477.html
    Mailing ListPatchVendor Advisory
  • xenbits.xenproject.org https://xenbits.xenproject.org/xsa/advisory-477.html
    MitigationPatchVendor Advisory