{"id":"ALPINE-CVE-2025-58148","details":"[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nSome Viridian hypercalls can specify a mask of vCPU IDs as an input, in\none of three formats.  Xen has boundary checking bugs with all three\nformats, which can cause out-of-bounds reads and writes while processing\nthe inputs.\n\n * CVE-2025-58147.  Hypercalls using the HV_VP_SET Sparse format can\n   cause vpmask_set() to write out of bounds when converting the bitmap\n   to Xen's format.\n\n * CVE-2025-58148.  Hypercalls using any input format can cause\n   send_ipi() to read d-\u003evcpu[] out-of-bounds, and operate on a wild\n   vCPU pointer.","modified":"2026-08-27T22:18:02.993876540Z","published":"2025-10-31T12:15:35.037Z","upstream":["CVE-2025-58148"],"references":[{"type":"ADVISORY","url":"https://security.alpinelinux.org/vuln/CVE-2025-58148"}],"affected":[{"package":{"name":"xen","ecosystem":"Alpine:v3.19","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.18.5-r3"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-58148.json"}},{"package":{"name":"xen","ecosystem":"Alpine:v3.20","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.18.5-r3"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-58148.json"}},{"package":{"name":"xen","ecosystem":"Alpine:v3.21","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.19.3-r2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-58148.json"}},{"package":{"name":"xen","ecosystem":"Alpine:v3.22","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.20.1-r2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-58148.json"}},{"package":{"name":"xen","ecosystem":"Alpine:v3.23","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.20.1-r2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-58148.json"}},{"package":{"name":"xen","ecosystem":"Alpine:v3.24","purl":"pkg:apk/alpine/xen?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.20.1-r2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2025-58148.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}