Hotfix XS82ECU1086 - For Citrix Hypervisor 8.2 Cumulative Update 1

Hotfix XS82ECU1086 - For Citrix Hypervisor 8.2 Cumulative Update 1

book

Article ID: CTX693229

calendar_today

Updated On:

Description

Who Should Install This Hotfix?

This is a hotfix for customers running Citrix Hypervisor 8.2 Cumulative Update 1 and is only available to customers on the Customer Success Services program.

All customers who are affected by the issues described in CTX693178 - Citrix Hypervisor Security Bulletin should install this hotfix.

Note: Citrix Hypervisor 8.2 Cumulative Update 1 reaches end of life on Jun 25, 2025. Upgrade to XenServer 8.4 before this date.

Where To Get This Hotfix

Download Citrix Hypervisor 8.2 Cumulative Update 1 hotfixes from the product downloads pages.

Information About this Hotfix

PrerequisiteXS82ECU1040
Post-update tasksRestart Host
Content live patchable**No
Baselines for Live PatchN/A
Revision History

Published on May 12, 2025

** Available to Premium Edition Customers.

Issues Resolved In This Hotfix

This security hotfix addresses the vulnerabilities as described in the Security Bulletin above. In addition, it includes the following changes:

  • Upstream code change for CVE-2025-1713 - deadlock potential with VT-d and legacy PCI device pass-through.

 

Note: Security mitigations for CPU hardware vulnerabilities can impact system performance. Any impacts are typically workload dependent.

This hotfix also includes the following previously released hotfixes:

Installing the Hotfix

Before you apply a hotfix, ensure that you have reviewed the prerequisites listed in Prepare a pool for an update in the Citrix Hypervisor documentation.

Customers should use either XenCenter or the Citrix Hypervisor Command Line Interface (CLI) to apply this hotfix. When the installation is complete, see the Post-update tasks in the table Information About this Hotfix for information about any post-update tasks you should perform for the update to take effect. As with any software update, back up your data before applying this update. Citrix recommends updating all servers within a pool sequentially. Upgrading of servers should be scheduled to minimize the amount of time the pool runs in a "mixed state" where some servers are upgraded and some are not. Running a mixed pool of updated and non-updated servers for general operation is not supported.

Installing the Hotfix by using XenCenter

Choose an Installation Mechanism

There are three mechanisms to install a hotfix:

  1. Automated Updates
  2. Download update from Citrix
  3. Select update or Supplemental pack from disk

The Automated Updates feature is available for Citrix Hypervisor Premium Edition customers, or to those who have access to XenServer through their Citrix Virtual Apps and Desktops entitlement. For information about installing a hotfix using the Automated Updates feature, see Apply Automated Updates in the Citrix Hypervisor documentation.

For information about installing a hotfix using the Download update from Citrix option, see Apply an Update to a Pool in the Citrix Hypervisor documentation.

The following section contains instructions on option (3) installing a hotfix that you have downloaded to disk:

  1. Download the hotfix to a known location on a computer that has XenCenter installed.
  2. Unzip the hotfix zip file and extract the .iso file
  3. In XenCenter, on the Tools menu, select Install Update. This displays the Install Update wizard.
  4. Read the information displayed on the Before You Start page and click Next to start the wizard.
  5. Click Browse to locate the iso file, select XS82ECU1086.iso and then click Open.
  6. Click Next.
  7. Select the pool or servers you wish to apply the hotfix to, and then click Next.
  8. The Install Update wizard performs a number of update prechecks, including the space available on the servers, to ensure that the pool is in a valid configuration state. The wizard also checks whether the servers need to be rebooted after the update is applied and displays the result.
  9. Choose the Update Mode. Review the information displayed on the screen and select an appropriate mode.
  10. Click Install update to proceed with the installation. The Install Update wizard shows the progress of the update, displaying the major operations that XenCenter performs while updating each server in the pool.
  11. When the update is applied, click Finish to close the wizard.
  12. If you chose to carry out the post-update tasks, do so now.

Installing the Hotfix by using the xe Command Line Interface

  1. Download the update file to a known location on the computer running the xe CLI.
  2. Extract the .iso file from the zip.
  3. Upload the .iso file to the main server of the pool by entering the following commands:
    (Where -s is the main server's IP address or DNS name.)
    xe -s <server> -u <username> -pw <password> update-upload file-name=<filename>/XS82ECU1086
    Citrix Hypervisor assigns the update file a UUID which this command prints. Note the UUID.
    57cdb475-50ab-4dca-a19c-36cd2678ded4
  4. Apply the update to all servers in the pool, specifying the UUID of the update:
    xe update-pool-apply uuid=57cdb475-50ab-4dca-a19c-36cd2678ded4

    Alternatively, if you need to update and restart servers in a rolling manner, you can apply the update file to an individual server by running the following:

    xe update-apply host=<server> uuid=57cdb475-50ab-4dca-a19c-36cd2678ded4

     

    If the server is a member of a pool, ensure that you update the pool master for Citrix Hypervisor 8.2 CU1 before you update any other pool member.

  5. Verify that the update was applied by using the update-list command.
    xe update-list -s <server> -u root -pw <password> name-label=XS82ECU1086
    If the update is successful, the hosts field contains the UUIDs of the servers to which this update was successfully applied. This should be a complete list of all servers in the pool.
  6. If the hotfix is applied successfully, restart each server in the pool, starting with the main server.
  7. Use the update-pool-clean command to remove the update files from all servers in the pool. This command frees up space on shared storage and does not uninstall the update.
    xe update-pool-clean uuid=57cdb475-50ab-4dca-a19c-36cd2678ded4

Hotfix Source

This source code is not necessary for hotfix installation. It is provided to fulfill licensing obligations.

Download the hotfix source from the following link: XS82ECU1086-sources.iso.

Files

Hotfix File

ComponentDetails
Hotfix FilenameXS82ECU1086.iso
Hotfix File sha256795971e752eed2f96990e2738f274bb2f5d69c0b1a867a5188e45b35dd18974b
Hotfix Source FilenameXS82ECU1086-sources.iso
Hotfix Source File sha256637b9cda077e1b62b44888770dc7ce3d2362ea72b8625307c435f7debaa0dd09
Hotfix Zip FilenameXS82ECU1086.zip
Hotfix Zip File sha256b1d4bc8ba2ae53f46a0ce7260457299f2ee2891e6179c45b5b2c82ffc65de4e5
Size of the Zip file58.45 MiB

Files Updated

edk2-20180522git4b8552d-1.4.6.x86_64.rpm
linux-firmware-20190314-11.xs8~2_1.noarch.rpm
microcode_ctl-2.1-26.xs34.xs8~2_1.x86_64.rpm
xen-dom0-libs-4.13.5-9.49.xs8~2_1.x86_64.rpm
xen-dom0-tools-4.13.5-9.49.xs8~2_1.x86_64.rpm
xen-hypervisor-4.13.5-9.49.xs8~2_1.x86_64.rpm
xen-libs-4.13.5-9.49.xs8~2_1.x86_64.rpm
xen-tools-4.13.5-9.49.xs8~2_1.x86_64.rpm

More Information

For a list of the minimum set of hotfixes you must apply to get your pool up to date, see Recommended Hotfixes for Citrix Hypervisor 8.2 Cumulative Update 1.

For more information, see Citrix Hypervisor Documentation.

If you experience any difficulties, contact Citrix Technical Support.