This is a hotfix for customers running Citrix Hypervisor 8.2 Cumulative Update 1.
All customers who are affected by the issues described in CTX691115 - XenServer and Citrix Hypervisor Security Update for CVE-2024-31143 and CVE-2024-31144 should install this hotfix.
Note: This hotfix is available only to customers on the Customer Success Services program.
Download Citrix Hypervisor 8.2 Cumulative Update 1 hotfixes from the product downloads pages.
Prerequisite | None |
Post-update tasks | Restart the XAPI Toolstack |
Content live patchable** | N/A |
Baselines for Live Patch | N/A |
Revision History |
Published on Jul 16, 2024 |
** Available to Premium Edition Customers. |
This security hotfix addresses the vulnerabilities as described in the Security Bulletin above.
In addition, this hotfix resolves the following issues:
This hotfix changes the behavior of the VM metadata backup and restore feature. For more information, see Backup and restore capabilities in XenServer xsconsole.
This hotfix also includes the following previously released hotfixes:
Customers should use either XenCenter or the Citrix Hypervisor Command Line Interface (CLI) to apply this hotfix. As with any software update, back up your data before applying this update. Citrix recommends updating all servers within a pool sequentially. Upgrading of servers should be scheduled to minimize the amount of time the pool runs in a "mixed state" where some servers are upgraded and some are not. Running a mixed pool of updated and non-updated servers for general operation is not supported.
There are three mechanisms to install a hotfix:
The Automated Updates feature is available for Citrix Hypervisor Premium Edition customers, or to those who have access to XenServer through their Citrix Virtual Apps and Desktops entitlement. For information about installing a hotfix using the Automated Updates feature, see the Applying Automated Updates in the Citrix Hypervisor documentation.
For information about installing a hotfix using the Download update from Citrix option, see Applying an Update to a Pool in the Citrix Hypervisor documentation.
The following section contains instructions on option (3) installing a hotfix that you have downloaded to disk:
Follow the on-screen recommendations to resolve any update prechecks that have failed. If you want XenCenter to automatically resolve all failed prechecks, click Resolve All. When the prechecks have been resolved, click Next.
Note: If you click Cancel at this stage, the Install Update wizard reverts the changes and removes the update file from the server.
xe -sCitrix Hypervisor assigns the update file a UUID which this command prints. Note the UUID.<server>
-u<username>
-pw<password>
update-upload file-name=<filename>
/XS82ECU1066.iso
2e5cfaed-c6db-43ef-a33a-29f02f994b10
xe update-pool-apply uuid=2e5cfaed-c6db-43ef-a33a-29f02f994b10
Alternatively, if you need to update and restart servers in a rolling manner, you can apply the update file to an individual server by running the following:
xe update-apply host=<server>
uuid=2e5cfaed-c6db-43ef-a33a-29f02f994b10
xe update-list -sIf the update is successful, the hosts field contains the UUIDs of the servers to which this update was successfully applied. This should be a complete list of all servers in the pool.<server>
-u root -pw<password>
name-label=XS82ECU1066
xe-toolstack-restartNote: When this command is run on the main server of the pool, XenCenter loses connection to the pool. Wait for 30 seconds after losing connection, and then reconnect manually.
xe update-pool-clean uuid=2e5cfaed-c6db-43ef-a33a-29f02f994b10
This source code is not necessary for hotfix installation. It is provided to fulfill licensing obligations.
Download the hotfix source from the following link: XS82ECU1066-sources.iso.
Component | Details |
---|---|
Hotfix Filename | XS82ECU1066.iso |
Hotfix File sha256 | ada948676142c6218a77cba6a212cec819c02478ccf95e92b5284f67429798f5 |
Hotfix Source Filename | XS82ECU1066-sources.iso |
Hotfix Source File sha256 | dcfff8bc9c3e1b971194ec7a5162285284485a3d2c2ad4a6dd3e8256672da2c3 |
Hotfix Zip Filename | XS82ECU1066.zip |
Hotfix Zip File sha256 | 96cb6607ac6c460dc7473fe73566f28b962ae3c3009d4675147aff8994cefd37 |
Size of the Zip file | 65.88 MB |
forkexecd-1.18.3-11.xs8~2_1.x86_64.rpm |
gpumon-0.18.0-19.xs8~2_1.x86_64.rpm |
message-switch-1.23.2-18.xs8~2_1.x86_64.rpm |
rrd2csv-1.2.6-16.xs8~2_1.x86_64.rpm |
rrdd-plugins-1.10.9-13.xs8~2_1.x86_64.rpm |
sm-cli-0.23.0-62.xs8~2_1.x86_64.rpm |
squeezed-0.27.0-19.xs8~2_1.x86_64.rpm |
v6d-citrix-10.53.3-8.xs8~2_1.x86_64.rpm |
varstored-guard-0.6.2-16.xs8~2_1.x86_64.rpm |
vhd-tool-0.43.0-19.xs8~2_1.x86_64.rpm |
wsproxy-1.12.0-20.xs8~2_1.x86_64.rpm |
xapi-clusterd-0.50.3-14.xs8~2_1.x86_64.rpm |
xapi-core-1.249.37-1.xs8~2_1.x86_64.rpm |
xapi-nbd-1.11.0-18.xs8~2_1.x86_64.rpm |
xapi-storage-script-0.34.1-17.xs8~2_1.x86_64.rpm |
xapi-xe-1.249.37-1.xs8~2_1.x86_64.rpm |
xcp-networkd-0.56.2-16.xs8~2_1.x86_64.rpm |
xcp-rrdd-1.33.4-5.xs8~2_1.x86_64.rpm |
xenopsd-0.150.19-4.xs8~2_1.x86_64.rpm |
xenopsd-cli-0.150.19-4.xs8~2_1.x86_64.rpm |
xenopsd-xc-0.150.19-4.xs8~2_1.x86_64.rpm |
xsconsole-10.1.13.1-2.xs8~2_1.x86_64.rpm |
For more information, see Citrix Hypervisor Documentation.
If you experience any difficulties, contact Citrix Technical Support.