XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics

    • All categories
    • stormiS

      XCP-ng 8.3 updates announcements and testing

      Watching Ignoring Scheduled Pinned Locked Moved News
      470
      1 Votes
      470 Posts
      194k Views
      A
      @stormi Left side of chart is all VMS running. 1.5gb/s each vm's vdi ranges from 128gb - 256gb allocated. Actual disk spaced used not sure) [image: 1777315109407-screenshot_20260425_130107.png] The 200mb/s - 300mb/s on far right is just XO-CE running idle. [image: 1777315216499-screenshot_20260425_144314.png] So if each vm is consuming 300mb/s ish times 4 -5 vms would get close to the 1.5gb/s.
    • H

      89 vulnerabilities in XAPI / Citrix XenServer

      Watching Ignoring Scheduled Pinned Locked Moved Development
      2
      0 Votes
      2 Posts
      91 Views
      stormiS
      Hi. We are aware of this publication and have reviewed every of its claims over the last days. A few of the reported issues do represent real privilege escalation paths. However, they rely on XAPI’s advanced RBAC roles feature, which is not enabled or exposed by default in Xen Orchestra, XO Lite, or any of our standard documentation. In practice, the escalation path requires a specific setup: an XCP-ng pool connected to Active Directory for its user management, where a user is given access to the management network and is explicitly granted VM configuration rights (vm-admin XAPI role) via XAPI roles. Such a user could gain elevated host-level privileges beyond what was intended. As we don't actively promote or recommend this configuration, we believe very few users are using it. For the small group that might be, patched packages are in the testing phase, and we will release them shortly. CVEs are being assigned by the Xen Project (which is the parent project of the XAPI Project) to the vulnerabilities, all requiring this vm-admin XAPI role. Most of the other claims stem from misunderstandings of how XAPI roles are designed to work (~65 of the 89 claims), or describe bugs that don’t translate to actual security impact (~15 of them). On the disclosure process: we always appreciate coordinated security research, but responsible disclosure typically involves a reasonable grace period (often two weeks or more) to allow time for review, patching, and coordinated release. In this case, we received an email just 24 hours before public publication, and the initial contact came with strange conditions. That doesn’t align with standard responsible disclosure practices. Note: This is not intended as an official statement. I have a clear view of the security impact, but since this is an informal, unfiltered write-up, please pardon any minor mistakes in how I’ve reported it.
    • olivierlambertO

      🛰️ XO 6: dedicated thread for all your feedback!

      Watching Ignoring Scheduled Pinned Locked Moved Xen Orchestra
      182
      7 Votes
      182 Posts
      23k Views
      G
      @escape222 Maybe try again as a BIOS boot VM, but the times for BIOS boot are nearing an end, so many things have climbed on UEFI only these days that a problem like this is going to be hard to ignore.
    • B

      The Lowest Priority Bug Ever? (/etc/udev/rules.d/z10-xen-vcpu-hotplug.rules)

      Watching Ignoring Scheduled Pinned Locked Moved XCP-ng
      4
      0 Votes
      4 Posts
      299 Views
      B
      @Team-OS-Platform-Release , lowest priority ever, but any thoughts on the topic at hand?
    • M

      CR backup with retention > 4

      Watching Ignoring Scheduled Pinned Locked Moved Backup
      3
      0 Votes
      3 Posts
      166 Views
      florentF
      @McHenry said: oo many snapshots the warning limit is 3 this make sense for a VM used for daily production, but we should maybe don't apply the same limit on replicated VM