QID 377771

QID 377771: Citrix XenServer Security Updates (CTX461397)

AMD has disclosed an issue that affects AMD CPU hardware and may allow code inside a guest VM to infer the contents of RAM memory elsewhere on the host. Although this is not an issue in the Citrix Hypervisor product itself, Citrix is releasing hotfixes that include product changes to mitigate this CPU hardware issue.

Affected Versions:
Citrix XenServer 7.1 CU2 LTSR Note: This QID will detect only for Citrix XenServer 7.1 LTSR

QID Detection Logic (Authenticated):
OS:Citrix XenServer
The QID checks if Hotfixes is applied on the vulnerable versions of Citrix XenServer.

Vulnerable version may allow code inside a guest VM to infer the contents of RAM memory elsewhere on the host.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Hotfixes have been released for Citrix XenServer to address these issues. Refer to CTX461397 to obtain more information.

    CVEs related to QID 377771

    Software Advisories
    Advisory ID Software Component Link
    CTX461397 URL Logo support.citrix.com/article/CTX461397/citrix-hypervisor-security-bulletin-for-cve202223816-and-cve202223825