CVE-2025-27465
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/07/2025
Last modified:
13/01/2026
Description
Certain instructions need intercepting and emulating by Xen. In some<br />
cases Xen emulates the instruction by replaying it, using an executable<br />
stub. Some instructions may raise an exception, which is supposed to be<br />
handled gracefully. Certain replayed instructions have additional logic<br />
to set up and recover the changes to the arithmetic flags.<br />
<br />
For replayed instructions where the flags recovery logic is used, the<br />
metadata for exception handling was incorrect, preventing Xen from<br />
handling the the exception gracefully, treating it as fatal instead.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* | 4.9.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



