cbcvebase.
CVE-2025-27465
published 2025-07-16

CVE-2025-27465: Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some…

PriorityP419medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.55%
42.5th percentile
Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which is supposed to be handled gracefully. Certain replayed instructions have additional logic to set up and recover the changes to the arithmetic flags. For replayed instructions where the flags recovery logic is used, the metadata for exception handling was incorrect, preventing Xen from handling the the exception gracefully, treating it as fatal instead.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.17.5+72-g01140da4e8-1 (bookworm)xen 4.17.5+72-g01140da4e8-1 (bookworm)
xenxen>= 0 < 4.18.5-r14.18.5-r1
xenxen>= 0 < 4.18.5-r14.18.5-r1
xenxen>= 0 < 4.19.2-r24.19.2-r2
xenxen>= 0 < 4.20.1-r04.20.1-r0
xenxen>= 0 < 4.20.1-r04.20.1-r0
xenxen>= 0 < 4.17.5+72-g01140da4e8-14.17.5+72-g01140da4e8-1
xenxen>= 0 < 4.20.2+7-g1badcf5035-0+deb13u14.20.2+7-g1badcf5035-0+deb13u1
xenxen>= 0 < 4.20.2+7-g1badcf5035-14.20.2+7-g1badcf5035-1
xenxen>= 4.9.0

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.