CVE-2015-8555: Citrix Xenserver
High severity, CVSS 8.6. EPSS: 2.3% chance of exploitation in the next 30 days.
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.
Affected products
- Citrix Xenserver: version 6.0 only
- Xen Xen: version 4.3.0 only; version 4.3.1 only; version 4.3.2 only; version 4.3.3 only; version 4.3.4 only; version 4.4.0 only; …
Published 2016-04-13. Last modified 2026-06-17.