(1) TMEMCSAVEGETCLIENTWEIGHT, (2) TMEMCSAVEGETCLIENTCAP, (3) TMEMCSAVEGETCLIENTFLAGS and (4) TMEMCSAVEEND in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (NULL pointer dereference or memory corruption and host crash) or possibly have other unspecified impacts via a NULL client id.