CVE-2025-27465 Details
Description
Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which is supposed to be handled gracefully. Certain replayed instructions have additional logic to set up and recover the changes to the arithmetic flags. For replayed instructions where the flags recovery logic is used, the metadata for exception handling was incorrect, preventing Xen from handling the the exception gracefully, treating it as fatal instead.
A vulnerability exists in the Xen hypervisor on x86 systems, specifically in versions 4.9 and later. When certain instructions are intercepted and emulated, Xen may replay them using an executable stub. Some of these instructions can raise exceptions that are meant to be handled gracefully. However, for replayed instructions that involve recovering changes to the arithmetic flags, the exception handling metadata was incorrect. This flaw prevented Xen from managing the exception properly, leading to a fatal hypervisor crash.
Applying the appropriate patch resolves this issue. Patches for released versions are generally prepared to apply to the stable branches. For Xen 4.17.x, use the patch named 'xsa470-4.17.patch'. For Xen 4.18.x, use the 'xsa470.patch'.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/07/01/1 | CVE | Mailing ListThird Party Advisory |
| http://xenbits.xen.org/xsa/advisory-470.html | CVE | PatchVendor Advisory |
| https://xenbits.xenproject.org/xsa/advisory-470.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| xen xen | >= 4.9.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2026 | Initial Analysis | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 3, 2025 | CVE Modified | CVE |
| Jul 17, 2025 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | New CVE Received | [email protected] |