Categories

  • All news regarding Xen and XCP-ng ecosystem

    143 Topics
    4k Posts
    rzrR
    We pushed the tested updates to the xcp-ng-updates repository, check blog post for summary and related advisories: https://xcp-ng.org/blog/2026/06/02/june-2026-updates-1-for-xcp-ng-8-3-lts/ Thank you again for feedback we will try to address reported issues on next batch (to come soon). Note that some issues are not related to this specific update batch, but might have been introduced on previous ones (TBC).
  • Everything related to the virtualization platform

    1k Topics
    15k Posts
    R
    Just a quick update for anyone following this thread—I decided to test this out on my end to verify the impact. After installing gcc in Dom0 and making a few necessary tweaks to the PoC code, I was able to successfully compile and run it. I managed to gain root access starting from a standard, unprivileged account. Based on this, I can confirm that a fully patched XCP-ng 8.3 system is indeed vulnerable to this attack. However, I want to strongly emphasize a key point about the threat model here so we keep the risk in perspective: this is strictly a Local Privilege Escalation (LPE) vulnerability. An attacker cannot just trigger this remotely. To exploit this, someone absolutely must already have a provisioned account with access to your Dom0. If you are following best practices and strictly controlling who (and what) has shell access to Dom0, your immediate, real-world risk is significantly mitigated. Hopefully, this helps clarify the exposure for everyone while we wait for an official patch upstream.
  • 3k Topics
    28k Posts
    FagnerMoraesF
    @pierrebrunet yes is encrypted!
  • Our hyperconverged storage solution

    47 Topics
    750 Posts
    olivierlambertO
    Please disable HA and report if you still have the issue.
  • 35 Topics
    113 Posts
    olivierlambertO
    Ah excellente nouvelle Je passe le sujet en résolu !