CVE-2016-9817: Xen

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.

Affected products

  • Xen Xen: version 4.7.0 only; version 4.7.1 only

Published 2017-02-27. Last modified 2026-06-17.