Database/Kernel, userspace & hypervisor

Xen (Viridian): Incorrect input sanitisation in Viridian (Hyper-V enlightenment) hypercalls
UnscoredCVE-2025-58147Kernel, userspace & hypervisorXSA-475curated
Impact
Incorrect input sanitisation in Viridian (Hyper-V enlightenment) hypercalls - guest attacks the hypervisor
Who can reach it
Tenant VM guest (Windows guests using Viridian)
What to do
Hypervisor patch + reboot/evacuation
References
Related entries
- Linux kernel bpf: BPF_REFCOUNT field was not marked unique in the verifier's field checksCVE-2026-100074 · Linux kernel BPF verifier (bpf_refcount not marked as a unique field)Unscored
- Xen (EPT): Use-after-free of EPT paging structures - HVM guest to host compromiseCVE-2026-23554 · Xen (EPT)Unscored
- OpenSSL: certificate with many relative-name CRL distribution points inflates heap on TLS handshakeCVE-2026-35189 · OpenSSL X.509 extension caching (CRL distribution points, nameRelativeToCRLIssuer)Unscored
- OpenSSL QUIC server: per-packet credit accounting breaks the RFC 9000 3x amplification limitCVE-2026-35191 · OpenSSL QUIC server (unvalidated address amplification credit accounting)Unscored
- Xen (x86 HVM): x86 HVM I/O port list traversal flawCVE-2026-42487 · Xen (x86 HVM)Unscored
- OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window framesCVE-2026-42772 · OpenSSL QUIC stream reassembly (out-of-order frame buffer list)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.