cbcvebase.
CVE-2025-58150
published 2026-01-28

CVE-2025-58150: Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled…

PriorityP346high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
2.8th percentile
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.20.2+37-g61ff35323e-1 (forky)xen 4.20.2+37-g61ff35323e-1 (forky)
xenxen>= 0 < 4.18.5-r44.18.5-r4
xenxen>= 0 < 4.19.4-r14.19.4-r1
xenxen>= 0 < 4.20.2-r14.20.2-r1
xenxen>= 0 < 4.20.2-r14.20.2-r1
xenxen>= 0 < 4.20.2+37-g61ff35323e-0+deb13u14.20.2+37-g61ff35323e-0+deb13u1
xenxen>= 0 < 4.20.2+37-g61ff35323e-14.20.2+37-g61ff35323e-1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.