CVE-2016-9381: Citrix Xenserver
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
Affected products
- Citrix Xenserver: version 6.0.2 only; version 6.2.0 only; version 6.5 only; version 7.0 only
- Qemu Qemu: up to and including 2.7.1; version 2.8.0 only
Published 2017-01-23. Last modified 2026-06-17.