Database/Kernel, userspace & hypervisor

Xen / x86 CPU: Floating Point Divider State Sampling - transient-execution leak of FP divider state across domains
UnscoredCVE-2025-54505Kernel, userspace & hypervisorXSA-488curated
Impact
Floating Point Divider State Sampling - transient-execution leak of FP divider state across domains
Who can reach it
Tenant VM guest; any tenant process in a container
What to do
Microcode + hypervisor/kernel mitigation + reboot; standing perf cost on FP-heavy workloads
References
Related entries
- Xen (Viridian): Incorrect input sanitisation in Viridian (Hyper-V enlightenment) hypercallsCVE-2025-58147 · Xen (Viridian)Unscored
- Linux kernel bpf: BPF_REFCOUNT field was not marked unique in the verifier's field checksCVE-2026-100074 · Linux kernel BPF verifier (bpf_refcount not marked as a unique field)Unscored
- Xen (EPT): Use-after-free of EPT paging structures - HVM guest to host compromiseCVE-2026-23554 · Xen (EPT)Unscored
- OpenSSL: certificate with many relative-name CRL distribution points inflates heap on TLS handshakeCVE-2026-35189 · OpenSSL X.509 extension caching (CRL distribution points, nameRelativeToCRLIssuer)Unscored
- OpenSSL QUIC server: per-packet credit accounting breaks the RFC 9000 3x amplification limitCVE-2026-35191 · OpenSSL QUIC server (unvalidated address amplification credit accounting)Unscored
- Xen (x86 HVM): x86 HVM I/O port list traversal flawCVE-2026-42487 · Xen (x86 HVM)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.