PT-2026-5017 · Xen+1 · Varstored+1

·

CVE-2025-58151

·

Published

2026-01-27

·

Updated

2026-07-09

CVSS v4.0

9.4

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The varstored component of the Xapi toolstack, which manages UEFI Variables for virtual machines, contains insufficient compiler barriers. This leads to Time-of-Check to Time-of-Use (TOCTOU) issues—a race condition where data is modified between the time it is checked and the time it is used—within a shared buffer used for communication with OVMF inside the VM. Depending on the compiler settings, an attacker may be able to control an index used in a jump table.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58151

Affected Products

Varstored
Xen