Hint from upstream. Sounds plausible that this might be the upstream fix:
9c17d96500f78 "xen/gntdev: Grant maps should not be subject to NUMA balancing"
I guess 4.3 started to be more aggressive there since I never saw this before 4.3 and there even on a non-NUMA system. But having a grant-table mapping taken away from the dom0 kernel without xenstored being involved would explain it tripping over that now bad pointer.
Hint from upstream. Sounds plausible that this might be the upstream fix:
9c17d96500f78 "xen/gntdev: Grant maps should not be subject to NUMA balancing"
I guess 4.3 started to be more aggressive there since I never saw this before 4.3 and there even on a non-NUMA system. But having a grant-table mapping taken away from the dom0 kernel without xenstored being involved would explain it tripping over that now bad pointer.