Xen · Varstored · CVE-2025-58151
**Name of the Vulnerable Software and Affected Versions**
Xen (affected versions not specified)
**Description**
The `varstored` component of the Xapi toolstack, which manages UEFI Variables for virtual machines, contains insufficient compiler barriers. This leads to Time-of-Check to Time-of-Use (TOCTOU) issues—a race condition where data is modified between the time it is checked and the time it is used—within a shared buffer used for communication with OVMF inside the VM. Depending on the compiler settings, an attacker may be able to control an index used in a jump table.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.