Логотип exploitDog
bind:"GHSA-64c5-3xxf-ccjp" OR bind:"CVE-2025-58147"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-64c5-3xxf-ccjp" OR bind:"CVE-2025-58147"

Количество 10

Количество 10

github логотип

GHSA-64c5-3xxf-ccjp

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-58147

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-58147

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-58147

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explai ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-15608

около 2 месяцев назад

Уязвимость функции vpmask_set() кроссплатформенного гипервизора Xen операционной системы Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3793-1

около 2 месяцев назад

Security update for xen

EPSS: Низкий
redos логотип

ROS-20251124-08

25 дней назад

Множественные уязвимости xen

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3843-1

около 2 месяцев назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3798-1

около 2 месяцев назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3797-1

около 2 месяцев назад

Security update for xen

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-64c5-3xxf-ccjp

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2025-58147

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-58147

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-58147

[This CNA information record relates to multiple CVEs; the text explai ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2025-15608

Уязвимость функции vpmask_set() кроссплатформенного гипервизора Xen операционной системы Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3793-1

Security update for xen

около 2 месяцев назад
redos логотип
ROS-20251124-08

Множественные уязвимости xen

CVSS3: 7.5
25 дней назад
suse-cvrf логотип
SUSE-SU-2025:3843-1

Security update for xen

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3798-1

Security update for xen

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3797-1

Security update for xen

около 2 месяцев назад

Уязвимостей на страницу