{"schema_version":"1.7.5","id":"CVE-2025-58148","published":"2025-10-31T12:15:35.037Z","modified":"2026-04-16T04:36:28.182362301Z","related":["SUSE-SU-2025:3793-1","SUSE-SU-2025:3797-1","SUSE-SU-2025:3798-1","SUSE-SU-2025:3843-1","SUSE-SU-2026:0012-1"],"details":"[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nSome Viridian hypercalls can specify a mask of vCPU IDs as an input, in\none of three formats.  Xen has boundary checking bugs with all three\nformats, which can cause out-of-bounds reads and writes while processing\nthe inputs.\n\n * CVE-2025-58147.  Hypercalls using the HV_VP_SET Sparse format can\n   cause vpmask_set() to write out of bounds when converting the bitmap\n   to Xen's format.\n\n * CVE-2025-58148.  Hypercalls using any input format can cause\n   send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild\n   vCPU pointer.","affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58148.json","unresolved_ranges":[{"events":[{"introduced":"4.15.0"}]}]}}],"references":[{"type":"FIX","url":"https://xenbits.xenproject.org/xsa/advisory-475.html"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2025/10/21/1"},{"type":"FIX","url":"http://xenbits.xen.org/xsa/advisory-475.html"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}