Impact
The vulnerability arises from buffer overruns in Xen’s libfsimage iso9660 driver, where several length values are derived directly from attacker‑controlled on‑disk fields without validation. This flaw can corrupt memory in the host process that handles ISO images, potentially leading to denial of service or, if an attacker can influence the driver to execute code, arbitrary code execution. The impact is a compromise of the Xen host, exposing the entire virtualization stack to corruption or malicious activity.
Affected Systems
The affected system is the Xen hypervisor, specifically the libfsimage iso9660 handling component. The vulnerability is triggered when a xen host or guest processes a malicious ISO9660 image. Information about specific affected Xen versions is not provided in the data set, so any installation that uses the vulnerable libfsimage logic is at risk. Guests that employ the pygrub bootloader are additionally vulnerable because the boot process interacts with the iso9660 driver.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no publicly available exploits are noted. It is inferred that successful exploitation requires local or privileged access to the Xen host to supply a crafted ISO image, meaning the attack vector is most likely local configuration or maintenance scenarios rather than remote network attacks.
OpenCVE Enrichment
Debian DSA