CVE-2016-9382: Citrix Xenserver

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.

Affected products

  • Citrix Xenserver: version 6.0.2 only; version 6.2.0 only; version 6.5 only; version 7.0 only
  • Xen Xen: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.1.0 only; …

Published 2017-01-23. Last modified 2026-06-17.