CVE-2016-10025: Citrix Xenserver

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.

Affected products

  • Citrix Xenserver: version 6.0.2 only; version 6.2.0 only; version 6.5 only; version 7.0 only
  • Xen Xen: version 4.6.0 only; version 4.6.1 only; version 4.6.3 only; version 4.6.4 only; version 4.7.0 only; version 4.7.1 only; …

Published 2017-01-26. Last modified 2026-06-17.