NONE · 0

CVE-2025-58151

varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, th...

Vulnerability Description

varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers, creating TOCTOU issues with data in the shared buffer. The exact vulnerable behaviour depends on the code generated by the compiler. In a build of varstored using default settings, the attacker can control an index used in a jump table.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-58151?

CVE-2025-58151 is a documented vulnerability. varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, th...

How severe is CVE-2025-58151?

CVSS scoring is not yet available for CVE-2025-58151. Check NVD for updates.

Is there a patch for CVE-2025-58151?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.