CVE-2025-58148
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs.
the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d-vcpu[] out-of-bounds, and operate on a wild vCPU pointer.
HIGH · CVSS 7.5
EPSS 0.00031
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0