CVE-2025-58150
published 2026-01-28CVE-2025-58150: Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled…
PriorityP346high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
2.8th percentile
Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing. Some of these variables are written to
with guest controlled data, of guest controllable size. That size can
be larger than the variable, and bounding of the writes was missing.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.20.2+37-g61ff35323e-1 (forky) | xen 4.20.2+37-g61ff35323e-1 (forky) |
| xen | xen | >= 0 < 4.18.5-r4 | 4.18.5-r4 |
| xen | xen | >= 0 < 4.19.4-r1 | 4.19.4-r1 |
| xen | xen | >= 0 < 4.20.2-r1 | 4.20.2-r1 |
| xen | xen | >= 0 < 4.20.2-r1 | 4.20.2-r1 |
| xen | xen | >= 0 < 4.20.2+37-g61ff35323e-0+deb13u1 | 4.20.2+37-g61ff35323e-0+deb13u1 |
| xen | xen | >= 0 < 4.20.2+37-g61ff35323e-1 | 4.20.2+37-g61ff35323e-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-58150: Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing
osv·2026-01-28·CVSS 8.8
CVE-2025-58150 [HIGH] CVE-2025-58150: Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.
GHSA
GHSA-vq9r-cp35-p48q: Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing
ghsa_unreviewed·2026-01-28
CVE-2025-58150 [HIGH] CWE-787 GHSA-vq9r-cp35-p48q: Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing
Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing. Some of these variables are written to
with guest controlled data, of guest controllable size. That size can
be larger than the variable, and bounding of the writes was missing.
OSV
CVE-2025-58150: Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing
osv·2026-01-28·CVSS 8.8
CVE-2025-58150 [HIGH] CVE-2025-58150: Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing
Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing. Some of these variables are written to
with guest controlled data, of guest controllable size. That size can
be larger than the variable, and bounding of the writes was missing.
Debian
CVE-2025-58150: xen - Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome par...
vendor_debian·2025·CVSS 8.8
CVE-2025-58150 [HIGH] CVE-2025-58150: xen - Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome par...
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.20.2+37-g61ff35323e-1)
sid: resolved (fixed in 4.20.2+37-g61ff35323e-1)
trixie: resolved (fixed in 4.20.2+37-g61ff35323e-0+deb13u1)
No detection rules found.
No public exploits indexed.
2026-01-28
Published