New security update candidates for XCP-ng 8.3 LTS (kernel, xen, intel-microcode)
This release batch contains security fix on kernel, version updates, some bug fixes.
What changed
Virtualization & System
kernel: Update to 4.19.19-8.0.46.3
Fixes CVE-2026-43284 (used by the DirtyFrag and CopyFail2 exploits)
intel-microcode: Update to 20260416-1
Improve Intel support and security INTEL-SA-01420
xen: Update to 4.17.6-8.1
Minor bugfixes for x86 systems, including calibration of various timers and handling of PCI devices when disabling SR-IOV
Control plane
xapi: Update to 26.1.4
Minor NUMA fixes
UI
xo-lite: Update to 0.21.0
chore: upgrade dependencies with known security vulnerabilities (#9640)
These vulnerabilities are not believed to affect XO Lite itself. They are fixed as defence-in-depth.
Changelog
Versions:
gpumon: 24.1.0-83.2.xcpng8.3 -> 24.1.0-84.1.xcpng8.3
intel-microcode: 20260115-1.xcpng8.3 -> 20260416-1.xcpng8.3
kernel: 4.19.19-8.0.46.2.xcpng8.3 -> 4.19.19-8.0.46.3.xcpng8.3
xapi: 26.1.3-1.10.xcpng8.3 -> 26.1.4-3.1.xcpng8.3
xcp-featured: 1.1.8-6.xcpng8.3 -> 1.2.1-1.xcpng8.3
xen: 4.17.6-6.2.xcpng8.3 -> 4.17.6-8.1.xcpng8.3
xo-lite: 0.20.0-1.xcpng8.3 -> 0.21.0-1.xcpng8.3
Test on XCP-ng 8.3
yum clean metadata --enablerepo=xcp-ng-testing,xcp-ng-candidates
yum update --enablerepo=xcp-ng-testing,xcp-ng-candidates
reboot
The usual update rules apply: pool coordinator first, etc.
What to test
As usual, normal use and anything else you want to test.
Test window before official release of the updates
~1 day
We would like to thank users who reported feedback since our last call for testing:
@Andrew, @FritzGerald, @IgorGlock, @bufanda, @flakpyro, @manilx, @marcoi, @ovicz, @ph7.