https://seclists.org/oss-sec/2025/q3/159: Xen Security Advisory 474 v2 (CVE-2025-58146) - XAPI UTF-8 string handling
Published Sep 9, 2025
·Updated
Affected Software
1 affected component
XEN XAPI
Frequently Asked Questions
1
What is the severity of CVE-2025-58146?
The severity of CVE-2025-58146 is classified as critical due to its potential impact on the integrity and security of the XAPI database.
2
How do I fix CVE-2025-58146?
To fix CVE-2025-58146, update your Xen XAPI to the latest version that includes the sanitization improvements.
3
What systems are affected by CVE-2025-58146?
CVE-2025-58146 affects systems running Xen with XAPI that handles UTF-8 string input.
4
What are the risks associated with CVE-2025-58146?
The risks associated with CVE-2025-58146 include potential data corruption, unauthorized access, and exploitation of the XAPI interface.
5
Is there a workaround for CVE-2025-58146 until a fix is applied?
A temporary workaround for CVE-2025-58146 may include disabling UTF-8 input processing in XAPI until the software is updated.