CVE-2025-58150

HIGH

Xen - Out-of-bounds Write in Shadow Mode Tracing Code

Title source: llm
STIX 2.1

Description

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.

References (3)

Core 3
Core References
Mitigation, Patch, Vendor Advisory
https://xenbits.xenproject.org/xsa/advisory-477.html
Mailing List, Mitigation, Patch, Third Party Advisory
http://www.openwall.com/lists/oss-security/2026/01/27/1
Mailing List, Patch, Vendor Advisory
http://xenbits.xen.org/xsa/advisory-477.html

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 4.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
xen/xen
Published Jan 28, 2026
Tracked Since Feb 18, 2026