Xen 4.6.3-3 packages, with XSA-190, are currently making their way through the build system. The vulnerability is an intra-guest information leak (i.e., between different processes in the same VM).
More information here:
https://xenbits.xen.org/xsa/advisory-190.html
-George