CVE-2025-58150Disclosure(xen / xen)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch xen xen systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xen

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-01-28); latest day: 3
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
xen

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 3d
01223Mentions · 2026-01-27: 2Mentions · 2026-01-28: 3Mentions · 2026-01-30: 3Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 2Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-30: 301-2701-2801-30
Signal classification3 categories
Disclosure
337.5%
Patch
337.5%
General
225.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1General1
2026-01-283
Disclosure1General1Patch1
2026-01-303
Disclosure1Patch2
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    3 new Xen Security Advisories https://www.openwall.com/lists/oss-security/2026/01/27/ 477 CVE-2025-58150 x86: buffer overrun with shadow paging + tracing 478 CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory 479 CVE-2026-23553 x86: incomplete IBPB for vCPU isolation

    Post summary

    Three new Xen security advisories are announced, listing CVEs with brief technical details but no PoC, exploit, or patch information is provided.

    01073739
    4.4K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-23553 x86: incomplete IBPB for vCPU isolation CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory CVE-2025-58150 x86: buffer overrun with shadow paging + tracing Xen Security Advisories https://xenbits.xen.org/xsa/

    Post summary

    The passage lists three Xen-related CVEs with short technical notes and provides a link to Xen Security Advisories, but it lacks evidence of PoC, exploit code, active exploitation, patches, or false‑positive claims.

    10000376
    6.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Attention System Administrators & DevOps Teams! 🚨 Mageia has released a critical security update, MGASA-2026-0026, patching two high-severity Xen hypervisor vulnerabilities (CVE-2025-58150 & CVE-2026-23553). Read more: 👉 https://tinyurl.com/4uc6es63 #Security https://t.co/dY9T33dkPF

    Post summary

    Mageia has issued a critical patch (MGASA-2026-0026) addressing two high‑severity Xen hypervisor vulnerabilities (CVE-2025-58150 and CVE-2026-23553).

    00000101
    1.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Xen hypervisor has a HIGH severity out-of-bounds write (CVE-2025-58150) in shadow mode tracing, exploitable by malicious guests. Update to 4.18.5-r4. #Xen #Virtualization #InfoSec https://www.pulsepatch.io/posts/cve-2025-58150-xen-shadow-mode-vulnerability

    Post summary

    CVE‑2025‑58150 is a HIGH severity out‑of‑bounds write in the Xen hypervisor’s shadow mode tracing, and users should apply the 4.18.5‑r4 update to remediate the issue.

    0000060
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A high severity out-of-bounds write (CVE-2025-58150) impacts Xen hypervisor shadow mode. Guest-controlled data can lead to memory corruption. Requires guest compromise. #Xen #Virtualization #InfoSec https://www.pulsepatch.io/posts/xen-hypervisor-shadow-mode-out-of-bounds-write-cve-2025-58150

    Post summary

    CVE-2025-58150 is a high‑severity out‑of‑bounds write vulnerability in Xen hypervisor shadow mode that can cause memory corruption when a guest is compromised.

    0000047
    1 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    URGENT: #openSUSE Leap 15.6 users must patch Xen hypervisor vulnerabilities CVE-2025-58150 (buffer overrun) and CVE-2026-23553 (incomplete IBPB). Read more: 👉 https://tinyurl.com/3yvpza8s #Security https://t.co/IgMwGkuP5z

    Post summary

    The tweet alerts openSUSE Leap 15.6 users to apply patches for two Xen hypervisor vulnerabilities, CVE-2025-58150 (buffer overrun) and CVE-2026-23553 (incomplete IBPB).

    0000047
    1.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-58150 Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of… https://www.cve.org/CVERecord?id=CVE-2025-58150

    Post summary

    The snippet mentions CVE-2025-58150 and notes that shadow mode tracing uses per‑CPU variables written with guest‑controlled data, but no additional technical, exploitation, or mitigation details are provided.

    00000147
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-58150 Xen Security Advisory 477 v2 (CVE-2025-58150) - x86 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-58150 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2025‑58150 with links to advisory and alert services but offers no technical, exploit, or mitigation details.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSxenxen--x86

Explore more