
=====================================================================

                           CERT-Renater

                 Note d'Information No. 2022/VULN023
_____________________________________________________________________

DATE                : 14/01/2022

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Citrix Hypervisor.

=====================================================================
https://support.citrix.com/article/CTX335432
_____________________________________________________________________

Citrix Hypervisor Security Update

Reference: CTX335432
Category : Medium
Created  : 12 January 2022
Modified : 12 January 2022

Applicable Products

  o Citrix Hypervisor

Description of Problem

Several security issues have been identified in Citrix Hypervisor, that
may each allow privileged code in a guest VM to cause the host to crash
or become unresponsive.

These issues have the following identifiers:

  o CVE-2021-28704
  o CVE-2021-28705
  o CVE-2021-28714
  o CVE-2021-28715

All of these issues affect all currently supported versions of Citrix
Hypervisor.

What Customers Should Do

Citrix has released hotfixes to address these issues. Citrix recommends
that affected customers install these hotfixes as their patching
schedule allows.
The hotfixes can be downloaded from the following locations:

Citrix Hypervisor 8.2 CU1 LTSR: CTX338448 -
https://support.citrix.com/article/CTX338448 and CTX335882 -
https://support.citrix.com/article/CTX335882

Citrix Hypervisor 8.2: CTX338444 -
https://support.citrix.com/article/CTX338444 and CTX335880 -
https://support.citrix.com/article/CTX335880

Citrix XenServer 7.1 LTSR CU2: CTX335531 -
https://support.citrix.com/article/CTX335531 and CTX335881 -
https://support.citrix.com/article/CTX335881

What Citrix is Doing

Citrix is notifying customers and channel partners about this potential
security issue. This article is also available from the Citrix Knowledge
Center at https://support.citrix.com/ .


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact
Citrix Technical Support. Contact details for Citrix Technical Support
are available at https://www.citrix.com/support/open-a-support-case/ .


Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and
considers any and all potential vulnerabilities seriously. For details
on our vulnerability response process and guidance on how to report
security-related issues to Citrix, please see the following webpage:
https://www.citrix.com/about/trust-center/vulnerability-process.html .


Disclaimer

This document is provided on an "as is" basis and does not imply any
kind of guarantee or warranty, including the warranties of
merchantability or fitness for a particular use. Your use of the
information on the document is at your own risk. Citrix reserves the
right to change or update this document at any time.


Changelog

Date       Change
2022-01-12 Initial Publication


=========================================================
+ CERT-RENATER            |    tel : 01-53-94-20-44
                                        +
+ 23/25 Rue Daviel         |    fax : 01-53-94-20-41
                                         +
+ 75013 Paris                  |    email:cert@support.renater.fr
                                        +
=========================================================

