---
id: CVE-2025-58151
title: |-
  varstored is a component of the Xapi toolstack handling UEFI Variables
  for a VM
summary: |-
  varstored is a component of the Xapi toolstack handling UEFI Variables
  for a VM.  It has a communication path with OVMF inside the VM involving
  mapping a buffer prepared by OVMF.

  Within varstored, there were insufficient compiler barrie…
severity: none
cwe:
  - CWE-367
published: '2026-07-09'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58151'
references:
  - url: 'https://xenbits.xen.org/xsa/advisory-478.html'
    label: security@xen.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/01/27/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://xenbits.xen.org/xsa/advisory-478.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00137
epssPercentile: 0.02601
ingestedAt: '2026-09-29T19:44:04.105Z'
---

## Overview

varstored is a component of the Xapi toolstack handling UEFI Variables
for a VM.  It has a communication path with OVMF inside the VM involving
mapping a buffer prepared by OVMF.

Within varstored, there were insufficient compiler barriers, creating
TOCTOU issues with data in the shared buffer.

The exact vulnerable behaviour depends on the code generated by the
compiler.  In a build of varstored using default settings, the attacker
can control an index used in a jump table.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
