
=====================================================================

                                CERT-Renater

                     Note d'Information No. 2022/VULN483

_____________________________________________________________________

DATE                : 22/12/2022

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Citrix Hypervisor versions prior
                                   to  8.2 LTSR CU1.

=====================================================================
https://support.citrix.com/article/CTX473048/citrix-hypervisor-security-bulletin-for-cve20223643-cve202242328-cve202242329
_____________________________________________________________________


Citrix Hypervisor Security Bulletin for CVE-2022-3643, CVE-2022-42328
& CVE-2022-42329

Reference: CTX473048
Category : Medium
Created  : 19 December 2022
Modified : 19 December 2022

Applicable Products

   o Citrix Hypervisor

Description of Problem

Several security issues have been identified in Citrix Hypervisor
8.2 LTSR CU1, each of which may allow a privileged user in a guest
VM to cause the host to become unresponsive or crash.
These issues have the following CVE identifiers:

   o CVE-2022-3643
   o CVE-2022-42328
   o CVE-2022-42329

What Customers Should Do

Citrix has released a hotfix to address these issues. Citrix
recommends that affected customers install this hotfix as their
patching schedule allows. The hotfix can be downloaded from the
following locations:
Citrix Hypervisor 8.2 LTSR CU1:
CTX476080 - https://support.citrix.com/article/
CTX476080


What Citrix is Doing

Citrix is notifying customers and channel partners about this
potential security issue through the publication of this security
bulletin on the Citrix Knowledge Center at
https://support.citrix.com/securitybulletins .


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact
Citrix Technical Support. Contact details for Citrix Technical Support
are available at https://www.citrix.com/support/open-a-support-case .


Subscribe to Receive Alerts

Citrix strongly recommends that all customers subscribe to receive
alerts when a Citrix security bulletin is created or modified at
https://support.citrix.com/user/alerts .


Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and
considers any and all potential vulnerabilities seriously. For
details on our vulnerability response process and guidance on how
to report security-related issues to Citrix, please see the following
webpage: 
https://www.citrix.com/about/trust-center/vulnerability-process.html .


Disclaimer

This document is provided on an "as is" basis and does not imply
any kind of guarantee or warranty, including the warranties of
merchantability or fitness for a particular use. Your use of the
information on the document is at your own risk. Citrix reserves the
right to change or update this document at any time. Customers are
therefore recommended to always view the latest version of
this document directly from the Citrix Knowledge Center.


Changelog

Date       Change
2022-12-19 Initial Publication

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================


