QID 377774

QID 377774: Citrix XenServer Security Updates (CTX341586)

An issue has been identified in AMD CPU hardware that may allow code in a guest VM to infer the value of in-memory data in other guest VMs. Although this is not an issue in the Citrix Hypervisor product itself, Citrix is releasing hotfixes that include mitigations for this hardware issue. This issue has the following identifier: CVE-2021-26401

Affected Products:
Citrix XenServer 7.1 CU2 LTSR Note: This QID will detect only for Citrix XenServer 7.1 LTSR

QID Detection Logic (Authenticated):
OS:Citrix XenServer
The QID checks if Hotfixes is applied on the vulnerable versions of Citrix XenServer.

Vulnerable version may allow code in a guest VM to infer the value of in-memory data in other guest VMs.

  • CVSS V3 rated as Medium - 5.6 severity.
  • CVSS V2 rated as Low - 1.9 severity.
  • Solution

    Hotfixes have been released for Citrix XenServer to address these issues. Refer to CTX341586 to obtain more information.

    CVEs related to QID 377774

    Software Advisories
    Advisory ID Software Component Link
    CTX341586 URL Logo support.citrix.com/article/CTX341586/citrix-hypervisor-security-update