CVE-2025-58151Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers, creating TOCTOU issues with data in the shared buffer. The exact vulnerable behaviour depends on the code generated by the compiler. In a build of varstored using default settings, the attacker can control an index used in a jump table.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-27); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-28: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 101-2701-28
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-01-281
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    3 new Xen Security Advisories https://www.openwall.com/lists/oss-security/2026/01/27/ 477 CVE-2025-58150 x86: buffer overrun with shadow paging + tracing 478 CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory 479 CVE-2026-23553 x86: incomplete IBPB for vCPU isolation

    Post summary

    The post announces three new Xen Security Advisories with brief technical details about each CVE, but does not include any PoC, exploit code, active exploitation claim, or patch information.

    01073739
    4.4K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CITRIX | Support XenServer Security Update for CVE-2025-58151 and CVE-2026-23553 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX695997&articleURL=XenServer_Security_Update_for_CVE_2025_58151_and_CVE_2026_23553

    Post summary

    The text announces a XenServer security update addressing CVE-2025-58151 and CVE-2026-23553, signaling available patches without providing PoC, exploit details, or evidence of active exploitation.

    01020397
    6.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-23553 x86: incomplete IBPB for vCPU isolation CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory CVE-2025-58150 x86: buffer overrun with shadow paging + tracing Xen Security Advisories https://xenbits.xen.org/xsa/

    Post summary

    The excerpt lists several Xen-related CVEs with brief technical descriptions and directs readers to Xen Security Advisories, indicating a disclosure of vulnerability information without mention of PoC, exploits, or patches.

    10000376
    6.7K followersView on X

Explore more