Hotfix XS82ECU1066 - For Citrix Hypervisor 8.2 Cumulative Update 1

Hotfix XS82ECU1066 - For Citrix Hypervisor 8.2 Cumulative Update 1

book

Article ID: CTX677991

calendar_today

Updated On:

Description

Who Should Install This Hotfix?

This is a hotfix for customers running Citrix Hypervisor 8.2 Cumulative Update 1.

All customers who are affected by the issues described in CTX691115 - XenServer and Citrix Hypervisor Security Update for CVE-2024-31143 and CVE-2024-31144 should install this hotfix.

Note: This hotfix is available only to customers on the Customer Success Services program.

Where To Get This Hotfix

Download Citrix Hypervisor 8.2 Cumulative Update 1 hotfixes from the product downloads pages.

Information About this Hotfix

PrerequisiteNone
Post-update tasksRestart the XAPI Toolstack
Content live patchable**N/A
Baselines for Live PatchN/A
Revision History

Published on Jul 16, 2024

** Available to Premium Edition Customers.

Issues Resolved In This Hotfix

This security hotfix addresses the vulnerabilities as described in the Security Bulletin above.

In addition, this hotfix resolves the following issues:

  • vGPU VM start fails with "No free virtual function found". As part of a start, resources like vGPU are allocated for a VM in "scheduled_to.." fields. These are not cleared when the VM start fails.
  • When external authentication is disabled for a pool, cached data is not cleared. As a result, stale information is displayed when the pool rejoins a domain. 
  • When creating an iSCSI SR by using xsconsole, xsconsole displays a "timed out" error message even when the SR is created successfully. 

This hotfix changes the behavior of the VM metadata backup and restore feature. For more information, see Backup and restore capabilities in XenServer xsconsole.

This hotfix also includes the following previously released hotfixes:

Installing the Hotfix

Customers should use either XenCenter or the Citrix Hypervisor Command Line Interface (CLI) to apply this hotfix. As with any software update, back up your data before applying this update. Citrix recommends updating all servers within a pool sequentially. Upgrading of servers should be scheduled to minimize the amount of time the pool runs in a "mixed state" where some servers are upgraded and some are not. Running a mixed pool of updated and non-updated servers for general operation is not supported.

Installing the Hotfix by using XenCenter

Choose an Installation Mechanism

There are three mechanisms to install a hotfix:

  1. Automated Updates
  2. Download update from Citrix
  3. Select update or Supplemental pack from disk

The Automated Updates feature is available for Citrix Hypervisor Premium Edition customers, or to those who have access to XenServer through their Citrix Virtual Apps and Desktops entitlement. For information about installing a hotfix using the Automated Updates feature, see the Applying Automated Updates in the Citrix Hypervisor documentation.

For information about installing a hotfix using the Download update from Citrix option, see Applying an Update to a Pool in the Citrix Hypervisor documentation.

The following section contains instructions on option (3) installing a hotfix that you have downloaded to disk:

  1. Download the hotfix to a known location on a computer that has XenCenter installed.
  2. Unzip the hotfix zip file and extract the .iso file
  3. In XenCenter, on the Tools menu, select Install Update. This displays the Install Update wizard.
  4. Read the information displayed on the Before You Start page and click Next to start the wizard.
  5. Click Browse to locate the iso file, select XS82ECU1066.iso and then click Open.
  6. Click Next.
  7. Select the pool or servers you wish to apply the hotfix to, and then click Next.
  8. The Install Update wizard performs a number of update prechecks, including the space available on the servers, to ensure that the pool is in a valid configuration state. The wizard also checks whether the servers need to be rebooted after the update is applied and displays the result.

Follow the on-screen recommendations to resolve any update prechecks that have failed. If you want XenCenter to automatically resolve all failed prechecks, click Resolve All. When the prechecks have been resolved, click Next.

  1. Choose the Update Mode. Review the information displayed on the screen and select an appropriate mode.

Note: If you click Cancel at this stage, the Install Update wizard reverts the changes and removes the update file from the server.

  1. Click Install update to proceed with the installation. The Install Update wizard shows the progress of the update, displaying the major operations that XenCenter performs while updating each server in the pool.
  2. When the update is applied, click Finish to close the wizard.
  3. If you chose to carry out the post-update tasks, do so now.

Installing the Hotfix by using the xe Command Line Interface

  1. Download the hotfix file to a known location.
  2. Extract the .iso file from the zip.
  3. Upload the .iso file to the main server of the pool by entering the following commands:
    (Where -s is the main server's IP address or DNS name.)
    xe -s <server> -u <username> -pw <password> update-upload file-name=<filename>/XS82ECU1066.iso
    Citrix Hypervisor assigns the update file a UUID which this command prints. Note the UUID.
    2e5cfaed-c6db-43ef-a33a-29f02f994b10
  4. Apply the update to all servers in the pool, specifying the UUID of the update:
    xe update-pool-apply uuid=2e5cfaed-c6db-43ef-a33a-29f02f994b10

    Alternatively, if you need to update and restart servers in a rolling manner, you can apply the update file to an individual server by running the following:

    xe update-apply host=<server> uuid=2e5cfaed-c6db-43ef-a33a-29f02f994b10

     

  5. Verify that the update was applied by using the update-list command.
    xe update-list -s <server> -u root -pw <password> name-label=XS82ECU1066
    If the update is successful, the hosts field contains the UUIDs of the servers to which this update was successfully applied. This should be a complete list of all servers in the pool.
  6. The hotfix is applied to all servers in the pool, but it will not take effect until the XAPI service is restarted on all servers. On the console of each server in the pool beginning with the main server, enter the following command to restart the XAPI service:
    xe-toolstack-restart
    Note: When this command is run on the main server of the pool, XenCenter loses connection to the pool. Wait for 30 seconds after losing connection, and then reconnect manually.
  7. Use the update-pool-clean command to remove the update files from all servers in the pool. This command frees up space on shared storage and does not uninstall the update.
    xe update-pool-clean uuid=2e5cfaed-c6db-43ef-a33a-29f02f994b10

Hotfix Source

This source code is not necessary for hotfix installation. It is provided to fulfill licensing obligations.

Download the hotfix source from the following link: XS82ECU1066-sources.iso.

 

Files

Hotfix File

ComponentDetails
Hotfix FilenameXS82ECU1066.iso
Hotfix File sha256ada948676142c6218a77cba6a212cec819c02478ccf95e92b5284f67429798f5
Hotfix Source FilenameXS82ECU1066-sources.iso
Hotfix Source File sha256dcfff8bc9c3e1b971194ec7a5162285284485a3d2c2ad4a6dd3e8256672da2c3
Hotfix Zip FilenameXS82ECU1066.zip
Hotfix Zip File sha25696cb6607ac6c460dc7473fe73566f28b962ae3c3009d4675147aff8994cefd37
Size of the Zip file65.88 MB

Files Updated

forkexecd-1.18.3-11.xs8~2_1.x86_64.rpm
gpumon-0.18.0-19.xs8~2_1.x86_64.rpm
message-switch-1.23.2-18.xs8~2_1.x86_64.rpm
rrd2csv-1.2.6-16.xs8~2_1.x86_64.rpm
rrdd-plugins-1.10.9-13.xs8~2_1.x86_64.rpm
sm-cli-0.23.0-62.xs8~2_1.x86_64.rpm
squeezed-0.27.0-19.xs8~2_1.x86_64.rpm
v6d-citrix-10.53.3-8.xs8~2_1.x86_64.rpm
varstored-guard-0.6.2-16.xs8~2_1.x86_64.rpm
vhd-tool-0.43.0-19.xs8~2_1.x86_64.rpm
wsproxy-1.12.0-20.xs8~2_1.x86_64.rpm
xapi-clusterd-0.50.3-14.xs8~2_1.x86_64.rpm
xapi-core-1.249.37-1.xs8~2_1.x86_64.rpm
xapi-nbd-1.11.0-18.xs8~2_1.x86_64.rpm
xapi-storage-script-0.34.1-17.xs8~2_1.x86_64.rpm
xapi-xe-1.249.37-1.xs8~2_1.x86_64.rpm
xcp-networkd-0.56.2-16.xs8~2_1.x86_64.rpm
xcp-rrdd-1.33.4-5.xs8~2_1.x86_64.rpm
xenopsd-0.150.19-4.xs8~2_1.x86_64.rpm
xenopsd-cli-0.150.19-4.xs8~2_1.x86_64.rpm
xenopsd-xc-0.150.19-4.xs8~2_1.x86_64.rpm
xsconsole-10.1.13.1-2.xs8~2_1.x86_64.rpm

More Information

For more information, see Citrix Hypervisor Documentation.

If you experience any difficulties, contact Citrix Technical Support.

Issue/Introduction

This is a hotfix for customers running Citrix Hypervisor 8.2 Cumulative Update 1 who are affected by the issues described in CTX691115 - XenServer and Citrix Hypervisor Security Update for CVE-2024-31143 and CVE-2024-31144.