They actually recently released information about this - there were multiple vulnerabilities in xen.civwould assume they were trying to keep the information quiet until the issue was fully resolved.
http://blog.linode.com/2012/06/13/xen-security-advisories-an...