An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
This issue has the following identifier:
CVE-2024-5661 affects all deployments.
CVE ID | Description | Pre-requisites | CWE |
CVE-2024-5661 | Potential Denial of Service | Privileged access within a guest VM | CWE-799 |
For customers using XenServer 8, we have pushed an update to both the Early Access and Normal update channels. We recommend that customers update to the latest version from their chosen channel following the instructions at https://docs.xenserver.com/en-us/xenserver/8/update
For customers using Citrix Hypervisor 8.2 CU1 LTSR, we have released a hotfix to address this issue. We recommend that customers install this hotfix and follow the instructions in the linked article as their update schedule permits. The hotfix can be downloaded from the following location:
CTX677067- https://support.citrix.com/article/CTX677067
2024-06-11 T 16:00:00Z | Initial Publication |
2024-07-13 T 15:15:00Z | Platform migration |