CVE-2016-9932: Xen
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Affected products
- Xen Xen: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; …
Published 2017-01-26. Last modified 2026-06-17.