Only HVM guests with one or more assigned PCI devices can leverage the issue. Environments running only PV guests, or HVM guests without assigned PCI devices, are not exposed to exploitation through this condition.
The attacker needs control of an HVM guest with assigned PCI devices. During guest termination, the guest can cause its device model to bind IRQs again after earlier cleanup has occurred, leaving at least one tracking structure uncollected.
Identify Xen hosts running HVM guests with PCI devices assigned to them. All Xen versions from at least 3.2 onward are affected; older versions were not inspected.
The issue leaks hypervisor memory. Repeated exploitation may exhaust host memory and cause denial of service affecting the entire host.