Shadow mode tracing code uses a set of per-CPU variables to avoid
cumbersome parameter passing. Some of these variables are written to
with guest controlled data, of guest controllable size. That size can
be larger than the variable, and bounding of the writes was missing.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xen
Xen xen |
|
| Vendors & Products |
Xen
Xen xen |
Wed, 28 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-787 | |
| Metrics |
cvssV3_1
|
Wed, 28 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing. | |
| Title | x86: buffer overrun with shadow paging + tracing | |
| References |
|
Status: PUBLISHED
Assigner: XEN
Published: 2026-01-28T15:33:17.316Z
Updated: 2026-01-28T16:46:04.355Z
Reserved: 2025-08-26T06:48:41.444Z
Link: CVE-2025-58150
Updated: 2026-01-28T16:11:53.448Z
Status : Awaiting Analysis
Published: 2026-01-28T16:16:12.880
Modified: 2026-01-29T16:31:00.867
Link: CVE-2025-58150
No data.