=====================================================================

                               CERT-Renater

                     Note d'Information No. 2024/VULN470
_____________________________________________________________________

DATE                : 15/11/2024

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running XenServer versions 8, 
           Citrix Hypervisor versions 8.2 CU1 LTSR.

=====================================================================
https://support.citrix.com/s/article/CTX692065-xenserver-and-citrix-hypervisor-security-update-for-cve202445818?language=en_US
_____________________________________________________________________

XenServer and Citrix Hypervisor Security Update for CVE-2024-45818

Title
     XenServer and Citrix Hypervisor Security Update for CVE-2024-45818

CTX Number
     CTX692065

Article Type
     Security Bulletin

Created Date
     12/Nov/2024

Last Modified Date
     13/Nov/2024

Severity
     Medium


Solution

     Description of Problem

     An issue has been identified that affects both XenServer 8
and Citrix Hypervisor 8.2 CU1 LTSR and allows a malicious
administrator of a guest VM to cause the host to crash or become
unresponsive.

     This issue has the following identifier:

         CVE-2024-45818

     What Customers Should Do

         For customers using XenServer 8, we have pushed updates
to both the Early Access and Normal update channels. We recommend
that customers update to the latest version from their chosen
channel following the instructions at
https://docs.xenserver.com/en-us/xenserver/8/update

         For customers using Citrix Hypervisor 8.2 CU1 LTSR, we have
released a hotfix to address this issue. We recommend that customers
install this hotfix and follow the instructions in the linked
article. The hotfix can be downloaded from the following location:

             CTX691830 - https://support.citrix.com/article/CTX691830

     What Are We Doing:
     We are notifying customers and channel partners about this
potential security issue through the publication of this security
bulletin on the Citrix Knowledge Center at
https://support.citrix.com/securitybulletins.

     Doing Obtaining Support on This Issue

     If you require technical assistance with this issue, please
contact Citrix Technical Support. Contact details for Citrix
Technical Support are available at https://www.citrix.com/support.

     Subscribe to Receive Alerts

     We strongly recommend that all customers subscribe to receive
alerts when a security bulletin is created or modified at
https://support.citrix.com/user/alerts.

     Reporting Security Vulnerabilities to Us

     We welcome input regarding the security of our products and
consider any and all potential vulnerabilities seriously. For
details on our vulnerability response process and guidance on
how to report security-related issues to us, please see the
following webpage:
https://www.citrix.com/about/trust-center/vulnerability-process.html.


     Disclaimer

     This document is provided on an "as is" basis and does not
imply any kind of guarantee or warranty, including the
warranties of merchantability or fitness for a particular use.
Your use of the information on the document is at your own risk.
Cloud Software Group reserves the right to change or update
this document at any time. Customers are therefore recommended
to always view the latest version of this document directly
from the Citrix Knowledge Center.


     Changelog
     2024-11-12	Initial Publication
     2024-11-12	Fixed the URL for CTX691830


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
