CVE-2025-58150
- EPSS 0.13%
- Veröffentlicht 28.01.2026 15:33:17
- Zuletzt bearbeitet 09.02.2026 19:13:28
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding o...
CVE-2025-58149
- EPSS 0.41%
- Veröffentlicht 31.10.2025 11:50:39
- Zuletzt bearbeitet 14.01.2026 22:04:31
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assigned to the...
CVE-2025-58147
- EPSS 0.36%
- Veröffentlicht 31.10.2025 11:50:28
- Zuletzt bearbeitet 14.01.2026 22:03:18
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking...
CVE-2025-58148
- EPSS 0.36%
- Veröffentlicht 31.10.2025 11:50:28
- Zuletzt bearbeitet 14.01.2026 22:03:32
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking...
CVE-2025-58144
- EPSS 0.45%
- Veröffentlicht 11.09.2025 14:05:36
- Zuletzt bearbeitet 04.11.2025 22:16:32
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, w...
CVE-2025-58145
- EPSS 0.35%
- Veröffentlicht 11.09.2025 14:05:36
- Zuletzt bearbeitet 04.11.2025 22:16:32
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, w...
CVE-2025-27466
- EPSS 0.47%
- Veröffentlicht 11.09.2025 14:05:29
- Zuletzt bearbeitet 04.11.2025 22:16:08
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL ...
CVE-2025-58142
- EPSS 0.47%
- Veröffentlicht 11.09.2025 14:05:29
- Zuletzt bearbeitet 04.11.2025 22:16:32
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL ...
CVE-2025-58143
- EPSS 0.37%
- Veröffentlicht 11.09.2025 14:05:29
- Zuletzt bearbeitet 04.11.2025 22:16:32
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL ...
CVE-2025-1713
- EPSS 0.72%
- Veröffentlicht 17.07.2025 13:59:46
- Zuletzt bearbeitet 13.01.2026 22:16:10
When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This...