cbcvebase.
CVE-2025-58147
published 2025-10-31

CVE-2025-58147: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can…

PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.36%
28.1th percentile
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in
one of three formats. Xen has boundary checking bugs with all three
formats, which can cause out-of-bounds reads and writes while processing
the inputs.

* CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can
cause vpmask_set() to write out of bounds when converting the bitmap
to Xen's format.

* CVE-2025-58148. Hypercalls using any input format can cause
send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild
vCPU pointer.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.17.5+72-g01140da4e8-1 (bookworm)xen 4.17.5+72-g01140da4e8-1 (bookworm)
xenxen>= 0 < 4.18.5-r34.18.5-r3
xenxen>= 0 < 4.18.5-r34.18.5-r3
xenxen>= 0 < 4.19.3-r24.19.3-r2
xenxen>= 0 < 4.20.1-r24.20.1-r2
xenxen>= 0 < 4.20.1-r24.20.1-r2
xenxen>= 0 < 4.17.5+72-g01140da4e8-14.17.5+72-g01140da4e8-1
xenxen>= 0 < 4.20.2+7-g1badcf5035-0+deb13u14.20.2+7-g1badcf5035-0+deb13u1
xenxen>= 0 < 4.20.2+7-g1badcf5035-14.20.2+7-g1badcf5035-1
xenxen>= 4.15.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.