CVE-2025-27465

4.3 MEDIUM
Published: July 16, 2025 Modified: January 13, 2026
View on NVD

Description

Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which is supposed to be handled gracefully. Certain replayed instructions have additional logic to set up and recover the changes to the arithmetic flags. For replayed instructions where the flags recovery logic is used, the metadata for exception handling was incorrect, preventing Xen from handling the the exception gracefully, treating it as fatal instead.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://xenbits.xenproject.org/xsa/advisory-470.html
Source: security@xen.org
Patch Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/07/01/1
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
http://xenbits.xen.org/xsa/advisory-470.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
4.3 / 10.0
EPSS (Exploit Probability)
0.1%
19th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

xen