CVE-2016-9378: Xen

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.

Affected products

  • Xen Xen: version 4.5.0 only; version 4.5.1 only; version 4.5.2 only; version 4.5.3 only; version 4.5.5 only; version 4.6.0 only; …

Published 2017-02-22. Last modified 2026-06-17.