Vulnerability record · CVE-2025-58150 · published 28 January 2026
CVE-2025-58150: Xen out-of-bounds write vulnerability
Xen · Xen
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.
Description
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://xenbits.xenproject.org/xsa/advisory-477.html | MitigationPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/01/27/1 | Mailing ListMitigationPatchThird Party Advisory |
| http://xenbits.xen.org/xsa/advisory-477.html | Mailing ListPatchVendor Advisory |
Track CVE-2025-58150 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-58150), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.