CVE-2016-9377: Xen

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

Affected products

  • Xen Xen: version 4.5.0 only; version 4.5.1 only; version 4.5.2 only; version 4.5.3 only; version 4.5.5 only; version 4.6.0 only; …

Published 2017-02-22. Last modified 2026-06-17.