CVE-2016-9385: Citrix Xenserver

Medium severity, CVSS 6.0. EPSS: 0.4% chance of exploitation in the next 30 days.

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.

Affected products

  • Citrix Xenserver: version 6.0.2 only; version 6.2.0 only; version 6.5 only; version 7.0 only
  • Xen Xen: version 4.4.0 only; version 4.4.1 only; version 4.4.2 only; version 4.4.3 only; version 4.4.4 only; version 4.5.0 only; …

Published 2017-01-23. Last modified 2026-06-17.