
===================================================================                             CERT-Renater

                  Note d'Information No. 2022/VULN140
______________________________________________________________________

DATE                : 06/04/2022
HARDWARE PLATFORM(S): /
OPERATING SYSTEM(S) : Systems running Citrix Hypervisor, XenServer.

====================================================================https://support.citrix.com/article/CTX390511
_______________________________________________________________________

Citrix Hypervisor Security Update

Reference: CTX390511
Category : Low
Created  : 05 April 2022
Modified : 05 April 2022

Applicable Products

  o Citrix Hypervisor
  o XenServer

Description of Problem

A security issue has been identified that affects Citrix Hypervisor.
This issue may allow privileged code in a guest VM to cause the host to
crash or become unresponsive. The issue only affects systems with Intel
CPUs where the malicious guest VM has had a physical PCI device assigned
to it by the host administrator using the PCI passthrough feature. The
issue has the following identifier:

  o CVE-2022-26357

Customers who have not assigned a physical PCI device to a guest VM are
not affected by this issue. Customers who are running on systems with
only AMD CPUs are also not affected by this issue.


What Customers Should Do

Citrix has released hotfixes to address this issue. Citrix recommends
that affected customers install these hotfixes as their patching
schedule allows.
The hotfixes can be downloaded from the following locations:
Citrix Hypervisor 8.2 CU1 LTSR: CTX376976 -
https://support.citrix.com/article/
CTX376976
Citrix Hypervisor 8.2: CTX376939 -
https://support.citrix.com/article/CTX376939
Citrix XenServer 7.1 CU2 LTSR: CTX376940 -
https://support.citrix.com/article/
CTX376940


What Citrix is Doing

Citrix is notifying customers and channel partners about this potential
security issue through the publication of this security bulletin on the
Citrix Knowledge Center at https://support.citrix.com/securitybulletins .


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact
Citrix Technical Support. Contact details for Citrix Technical Support
are available at https://www.citrix.com/support/open-a-support-case .


Subscribe to Receive Alerts

Citrix strongly recommends that all customers subscribe to receive
alerts when a Citrix security bulletin is created or modified at
https://support.citrix.com
/user/alerts .


Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and
considers any and all potential vulnerabilities seriously. For details
on our vulnerability response process and guidance on how to report
security-related issues to Citrix, please see the following webpage:
https://www.citrix.com/about/trust-center/vulnerability-process.html .


Disclaimer

This document is provided on an "as is" basis and does not imply any
kind of guarantee or warranty, including the warranties of
merchantability or fitness for a particular use. Your use of the
information on the document is at your
own risk. Citrix reserves the right to change or update this document at
any time. Customers are therefore recommended to always view the latest
version of this document directly from the Citrix Knowledge Center.


Changelog

Date         Change
2022-04-05   Initial Publication


========================================================+ CERT-RENATER      | tel : 01-53-94-20-44              +
+ 23/25 Rue Daviel  | fax : 01-53-94-20-41              +
+ 75013 Paris       | email:cert@support.renater.fr     +
=======================================================--------------mhJyVZPMWA9ol52tmW0vieLP--

