Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2026/VULN336
_____________________________________________________________________

DATE                : 27/03/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running XenServer versions  8.4.

=====================================================================
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696397&articleURL=XenServer_Security_Update_for_CVE_2026_4397
_____________________________________________________________________

XenServer Security Update for CVE-2026-4397
Article Id : CTX696397
Last Modified Date : 03-25-2026 07:28
Created Date : 03-18-2026 16:41
Article Record Type : Security Bulletin
Severity :  Medium


Summary

Severity: Medium

Description of Problem

An issue has been identified in XenServer 8.4 which, when starting a
VM on a host with limited available memory, may allow a privileged
user in that newly starting VM to access memory data of a previously
terminated VM. This issue has the following identifier:

    CVE-2026-4397


Affected Versions

This issue affects XenServer 8.4.

(Note that XenServer 9 is in Public Preview; releases in preview state
are not intended for production use and so are not covered by security
bulletins until they exit preview state.)


Details

What Customers Should Do

We have pushed updates to both the Early Access and Normal update channels 
of XenServer 8.4. We recommend that customers update to the latest version
from their chosen channel following the instructions at
https://docs.xenserver.com/en-us/xenserver/8/update 


What Citrix is Doing

We are notifying customers and channel partners about this potential security
issue through the publication of this security bulletin on the Citrix
Knowledge Center at
https://support.citrix.com/support-home/topic-article-list?trendingCategory=20&trendingTopicName=Security%20Bulletin 


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix
Technical Support. Contact details for Citrix Technical Support are available
at https://www.citrix.com/support
 

Subscribe to Receive Alerts

Citrix strongly recommends that all customers subscribe to receive alerts when
a security bulletin is created or modified at
https://support.citrix.com/wolken-support/view/aboutsupport/my-support-alerts 

Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and considers any
and all potential vulnerabilities seriously. For details on our vulnerability
response process and guidance on how to report security-related issues to Citrix,
please see the following webpage: https://www.cloud.com/trust-center/support 


Change Log
2026-03-24 	Initial Publication


Disclaimer

The information on this page is being provided to you on an "AS IS" and
"AS-AVAILABLE" basis. The issues described on this page may or may not impact
your system(s). Cloud Software Group, Inc. and its subsidiaries (collectively,
"Cloud SG") make no representations, warranties, or guarantees as to the
information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED,
INCLUDING, WITHOUT LIMITATION, INCLUDING, BUT NOT LIMITED TO, IMPLIED
WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR
PURPOSE ARE HEREBY DISCLAIMED. BY ACCESSING THIS PAGE, YOU ACKNOWLEDGE THAT
CLOUD SG SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE
TO USE THE INFORMATION CONTAINED HEREIN. Cloud SG reserves the right to
change or update the information on this page at any time. We accordingly
recommend that you always view the latest version of this page. The
information contained herein is being provided to you under the terms of
your applicable customer agreement with Cloud SG, and may be used only
for the purposes contemplated by such agreement. If you do not have such
an agreement with Cloud SG, this information is provided under the
cloud.com Terms of Use, and may be used only for the purposes contemplated
by such Terms of Use.


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




