Out-of-Bounds Read and Write in Viridian Hypercalls Affecting Xen Hypervisor
CVE-2025-58148 
7.5HIGH
What is CVE-2025-58148?
Multiple Viridian hypercalls in the Xen hypervisor can be manipulated to specify incorrect vCPU ID masks. This can result in boundary checking flaws across various formats, leading to out-of-bounds reads and writes. Consequently, an attacker could exploit this vulnerability to access unauthorized memory locations, potentially compromising system integrity and stability.
Affected Version(s)
Xen consult Xen advisory XSA-475