CVE-2016-10024: Citrix Xenserver

Medium severity, CVSS 6.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.

Affected products

  • Citrix Xenserver: version 6.0.2 only; version 6.2.0 only; version 6.5 only; version 7.0 only
  • Xen Xen: up to and including 4.8.0

Published 2017-01-26. Last modified 2026-06-17.