Apparently if you use CVE-2017-13672 in a HVM guest, it doesn't crash (no guard pages?), but instead leaks some Xen memory (which seems to contain guest kernel memory) via the VGA output. I don't think its useful for exploitation, but it looks cool/interesting.
