XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XCP-ng 8.3 updates announcements and testing

    Scheduled Pinned Locked Moved News
    678 Posts 56 Posters 598.6k Views 75 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      MajorP93 @rzr
      last edited by

      @rzr Since the targeted test window is over by now, I wonder: what are your plans regarding this set of patches? Will it be released soon?

      rzrR 1 Reply Last reply Reply Quote 1
      • rzrR Offline
        rzr Vates 🪐 XCP-ng Team @MajorP93
        last edited by rzr

        @MajorP93 said:

        @rzr Since the targeted test window is over by now, I wonder: what are your plans regarding this set of patches? Will it be released soon?

        yes this is the plan, we're a bit slower this time because the iso publication is a longer process, but afaik no issue are spotted so far, thank you for your patience.

        1 Reply Last reply Reply Quote 0
        • rzrR Offline
          rzr Vates 🪐 XCP-ng Team
          last edited by

          We pushed the tested packages along a xen security update to the xcp-ng-updates repository, check blog post for summary and related advisories:
          https://xcp-ng.org/blog/2026/07/28/july-2026-updates-1-for-xcp-ng-8-3-lts/

          M acebmxerA 2 Replies Last reply Reply Quote 1
          • M Offline
            MajorP93 @rzr
            last edited by MajorP93

            @rzr Thanks! How long does it take for these patches go be available?

            [17:00 xcpng01 ~]# yum update
            Geladene Plugins: fastestmirror
            Loading mirror speeds from cached hostfile
            Excluding mirror: updates.xcp-ng.org
             * xcp-ng-base: mirrors.xcp-ng.org
            Excluding mirror: updates.xcp-ng.org
             * xcp-ng-updates: mirrors.xcp-ng.org
            No packages marked for update
            
            

            //EDIT: Nevermind. After running yum clean metadata they are being picked up.

            1 Reply Last reply Reply Quote 3
            • acebmxerA Offline
              acebmxer @rzr
              last edited by

              @rzr said:

              We pushed the tested packages along a xen security update to the xcp-ng-updates repository, check blog post for summary and related advisories:
              https://xcp-ng.org/blog/2026/07/28/july-2026-updates-1-for-xcp-ng-8-3-lts/

              Just updated my homelab hosts.

              [10:45 xcp-ng-disjqdnc ~]# yum clean metadata
              Loaded plugins: fastestmirror
              Cleaning repos: xcp-ng-base xcp-ng-updates
              6 metadata files removed
              4 sqlite files removed
              0 metadata files removed
              [10:45 xcp-ng-disjqdnc ~]# yum update
              Loaded plugins: fastestmirror
              Loading mirror speeds from cached hostfile
              Excluding mirror: updates.xcp-ng.org
               * xcp-ng-base: mirrors.xcp-ng.org
              Excluding mirror: updates.xcp-ng.org
               * xcp-ng-updates: mirrors.xcp-ng.org
              xcp-ng-base/signature                                                                                                |  473 B  00:00:00     
              xcp-ng-base/signature                                                                                                | 3.0 kB  00:00:00 !!! 
              xcp-ng-updates/signature                                                                                             |  473 B  00:00:00     
              xcp-ng-updates/signature                                                                                             | 3.0 kB  00:00:00 !!! 
              (1/2): xcp-ng-base/primary_db                                                                                        | 3.9 MB  00:00:00     
              (2/2): xcp-ng-updates/primary_db                                                                                     | 1.6 MB  00:00:01     
              Resolving Dependencies
              --> Running transaction check
              ---> Package xen-dom0-libs.x86_64 0:4.17.6-9.3.xcpng8.3 will be updated
              ---> Package xen-dom0-libs.x86_64 0:4.17.6-9.3.1.xcpng8.3 will be an update
              ---> Package xen-dom0-tools.x86_64 0:4.17.6-9.3.xcpng8.3 will be updated
              ---> Package xen-dom0-tools.x86_64 0:4.17.6-9.3.1.xcpng8.3 will be an update
              ---> Package xen-hypervisor.x86_64 0:4.17.6-9.3.xcpng8.3 will be updated
              ---> Package xen-hypervisor.x86_64 0:4.17.6-9.3.1.xcpng8.3 will be an update
              ---> Package xen-libs.x86_64 0:4.17.6-9.3.xcpng8.3 will be updated
              ---> Package xen-libs.x86_64 0:4.17.6-9.3.1.xcpng8.3 will be an update
              ---> Package xen-tools.x86_64 0:4.17.6-9.3.xcpng8.3 will be updated
              ---> Package xen-tools.x86_64 0:4.17.6-9.3.1.xcpng8.3 will be an update
              --> Finished Dependency Resolution
              
              Dependencies Resolved
              
              ============================================================================================================================================
               Package                          Arch                     Version                                   Repository                        Size
              ============================================================================================================================================
              Updating:
               xen-dom0-libs                    x86_64                   4.17.6-9.3.1.xcpng8.3                     xcp-ng-updates                   704 k
               xen-dom0-tools                   x86_64                   4.17.6-9.3.1.xcpng8.3                     xcp-ng-updates                   2.0 M
               xen-hypervisor                   x86_64                   4.17.6-9.3.1.xcpng8.3                     xcp-ng-updates                   2.4 M
               xen-libs                         x86_64                   4.17.6-9.3.1.xcpng8.3                     xcp-ng-updates                    66 k
               xen-tools                        x86_64                   4.17.6-9.3.1.xcpng8.3                     xcp-ng-updates                    47 k
              
              Transaction Summary
              ============================================================================================================================================
              Upgrade  5 Packages
              
              Total download size: 5.2 M
              Is this ok [y/d/N]: y
              Downloading packages:
              Delta RPMs disabled because /usr/bin/applydeltarpm not installed.
              (1/5): xen-dom0-tools-4.17.6-9.3.1.xcpng8.3.x86_64.rpm                                                               | 2.0 MB  00:00:00     
              (2/5): xen-dom0-libs-4.17.6-9.3.1.xcpng8.3.x86_64.rpm                                                                | 704 kB  00:00:00     
              (3/5): xen-libs-4.17.6-9.3.1.xcpng8.3.x86_64.rpm                                                                     |  66 kB  00:00:00     
              (4/5): xen-hypervisor-4.17.6-9.3.1.xcpng8.3.x86_64.rpm                                                               | 2.4 MB  00:00:00     
              (5/5): xen-tools-4.17.6-9.3.1.xcpng8.3.x86_64.rpm                                                                    |  47 kB  00:00:00     
              --------------------------------------------------------------------------------------------------------------------------------------------
              Total                                                                                                       2.9 MB/s | 5.2 MB  00:00:01     
              Running transaction check
              Running transaction test
              Transaction test succeeded
              Running transaction
                Updating   : xen-libs-4.17.6-9.3.1.xcpng8.3.x86_64                                                                                   1/10 
                Updating   : xen-hypervisor-4.17.6-9.3.1.xcpng8.3.x86_64                                                                             2/10 
                Updating   : xen-dom0-libs-4.17.6-9.3.1.xcpng8.3.x86_64                                                                              3/10 
                Updating   : xen-tools-4.17.6-9.3.1.xcpng8.3.x86_64                                                                                  4/10 
                Updating   : xen-dom0-tools-4.17.6-9.3.1.xcpng8.3.x86_64                                                                             5/10 
                Cleanup    : xen-dom0-tools-4.17.6-9.3.xcpng8.3.x86_64                                                                               6/10 
                Cleanup    : xen-tools-4.17.6-9.3.xcpng8.3.x86_64                                                                                    7/10 
                Cleanup    : xen-dom0-libs-4.17.6-9.3.xcpng8.3.x86_64                                                                                8/10 
                Cleanup    : xen-hypervisor-4.17.6-9.3.xcpng8.3.x86_64                                                                               9/10 
                Cleanup    : xen-libs-4.17.6-9.3.xcpng8.3.x86_64                                                                                    10/10 
                Verifying  : xen-dom0-tools-4.17.6-9.3.1.xcpng8.3.x86_64                                                                             1/10 
                Verifying  : xen-dom0-libs-4.17.6-9.3.1.xcpng8.3.x86_64                                                                              2/10 
                Verifying  : xen-hypervisor-4.17.6-9.3.1.xcpng8.3.x86_64                                                                             3/10 
                Verifying  : xen-libs-4.17.6-9.3.1.xcpng8.3.x86_64                                                                                   4/10 
                Verifying  : xen-tools-4.17.6-9.3.1.xcpng8.3.x86_64                                                                                  5/10 
                Verifying  : xen-libs-4.17.6-9.3.xcpng8.3.x86_64                                                                                     6/10 
                Verifying  : xen-dom0-tools-4.17.6-9.3.xcpng8.3.x86_64                                                                               7/10 
                Verifying  : xen-hypervisor-4.17.6-9.3.xcpng8.3.x86_64                                                                               8/10 
                Verifying  : xen-tools-4.17.6-9.3.xcpng8.3.x86_64                                                                                    9/10 
                Verifying  : xen-dom0-libs-4.17.6-9.3.xcpng8.3.x86_64                                                                               10/10 
              
              Updated:
                xen-dom0-libs.x86_64 0:4.17.6-9.3.1.xcpng8.3 xen-dom0-tools.x86_64 0:4.17.6-9.3.1.xcpng8.3 xen-hypervisor.x86_64 0:4.17.6-9.3.1.xcpng8.3
                xen-libs.x86_64 0:4.17.6-9.3.1.xcpng8.3      xen-tools.x86_64 0:4.17.6-9.3.1.xcpng8.3
              
              1 Reply Last reply Reply Quote 3
              • T Offline
                TrapoSAMA
                last edited by

                Working fine latest update into DL360G7 🙂

                1 Reply Last reply Reply Quote 3
                • M Offline
                  MajorP93
                  last edited by

                  Installed these patches on a pool of 4 hosts, can confirm everything looking good!

                  1 Reply Last reply Reply Quote 2
                  • J Offline
                    JeffBerntsen Top contributor
                    last edited by

                    Just installed these onto my test systems including my twinstor guinea pigs and all seems good so far.

                    1 Reply Last reply Reply Quote 3
                    • marcoiM Offline
                      marcoi
                      last edited by

                      went well with test systems. going to do prod soon.

                      semarieS 1 Reply Last reply Reply Quote 1
                      • A Offline
                        andersonalipio
                        last edited by andersonalipio

                        Ran into some issues with sdncontroller.py (XCP-ng 8.3 and xcp-ng-xapi-plugins-1.16.0-1) when creating traffic rules on VLAN VIFs (and networks) in XOA — same error on both Premium and Community. The problem turned out to be a line feed sent by XOA.

                        On line 236 of sdncontroller.py, I added a fix that solved the problem, and it now works perfectly managing traffic rules in XO on VLAN networks:

                        def update_args_from_ovs(args):
                            # FIX: strip line feed (\n \X0a) sent by Xen Orchestra
                            args["bridge"] = str(args["bridge"]).strip()
                            # get parent...
                        

                        I had another problem when adding rules on networks that weren't connected on all hosts, because those hosts didn't have VMs running on that network (default). Manually connecting them worked fine.

                        I think it's more of an XO error than xapi plugin, but worked ok in my case.

                        Thanks for the great work!

                        bleaderB 1 Reply Last reply Reply Quote 0
                        • olivierlambertO Offline
                          olivierlambert Vates 🪐 Co-Founder CEO
                          last edited by

                          Ah good catch @andersonalipio ! We'll check that 🙂

                          Ping @Team-XAPI-Network

                          1 Reply Last reply Reply Quote 0
                          • semarieS Offline
                            semarie Vates 🪐 XCP-ng Team XAPI & Network Team @marcoi
                            last edited by

                            @andersonalipio I would be interested to get some elements from your installation.

                            • your /var/log/sdn-controller-plugin.log file (on the host) in order to check the parameter passed by XO.
                            • output of xe network-param-list uuid=$UUID (for the network concerned) or xe network-list params=all (if uuid is unknown)
                            • output of xe pool-list params=other-config (for xo:sdn-controller:* elements)
                            • output of xe vif-list params=uuid,network-uuid,other-config (for xo:sdn-controller:* elements)

                            Feel free to share it privately via PM if you prefer, possibly using https://paste.vates.tech/ .

                            Cc @Team-XO-Backend too (as it could be from XO side)

                            A 2 Replies Last reply Reply Quote 0
                            • bleaderB Offline
                              bleader Vates 🪐 XCP-ng Team @andersonalipio
                              last edited by

                              @andersonalipio can you also share the XOA version you're running? @semarie did a bunch of improvement on lifecycle of hosts and VM at some point XO side.

                              A 1 Reply Last reply Reply Quote 0
                              • A Offline
                                andersonalipio @semarie
                                last edited by

                                @semarie I'll do it as soon as I get access to the server, hopefully tomorrow.

                                1 Reply Last reply Reply Quote 0
                                • A Offline
                                  andersonalipio @bleader
                                  last edited by

                                  @bleader XOA 6.7 premium (updated last friday - latest channel), as all updates on XCP-ng 8.3 from latests available updates on same day (not testing, ci or other repos)

                                  1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    andersonalipio @semarie
                                    last edited by

                                    @semarie sorry for the delay.

                                    @semarie said:

                                    your /var/log/sdn-controller-plugin.log file (on the host) in order to check the parameter passed by XO.
                                    MASTER_sdn-controller-plugin.txt

                                    @semarie said:

                                    output of xe network-param-list uuid=$UUID (for the network concerned) or xe network-list params=all (if uuid is unknown)
                                    uuid ( RO) : 250cec4e-d7af-23c5-be1c-391186bde2f4
                                    name-label ( RW): VLAN VDI INT - 102
                                    name-description ( RW): VLAN Rede VDI Interna VMs
                                    VIF-uuids (SRO): 9f23be5a-a6f5-f64d-e004-4a432aded733; b9f85e54-cfd0-6546-edac-ba1573f00bc5; 16bfa5e3-4022-7c9e-ef43-735599b9b5f2; 418fc7cb-ab9c-23db-8bad-7854cb16cbcb; b9dfc5b9-560e-38ac-941a-f744b0d741d8; af16b830-1d31-c664-d70c-a6d1c7ce3056; 3596ec8a-d0ee-2468-d6ae-16b66c745d03; 181808cf-1c42-ddcb-13b5-3bf5f4483a3f; 0c576952-b1f1-95db-1a7e-fc8f581a46e3; b2b8da93-f07f-32a4-1ae1-ae2eac13da08; 9c96d442-e782-774a-ac98-858fcce36607; f512706b-f1a3-767d-6941-ed0f6c926291; c5f2e0b1-a8d2-4846-521a-54b790d6d849; 82b9789c-cf69-6382-e6cc-95ef67b0ba2e; 967ecb88-a141-cd17-c45f-9f5a779efbca; 7445be42-7b30-7a61-f3a1-6aadb725be6a; aa2e03aa-dc9c-aff3-d8cb-5c652af62958; dd596564-a3b4-e15f-69cf-2af5d128a8c2; 767a2bae-8ff0-45fd-339f-56a955ed1ada; e5c85ad8-4bc1-f8b6-6c31-ca6f48604920; d30dfed6-ba5c-04f8-bbc6-ddc18414737e; cddb92fd-da90-cce1-620c-c31469dccada; da4421fa-0bb5-525b-544e-f03e6fbce04b; 947932f8-4bf6-204f-d112-0b251ac4abae; b5bdddd6-2908-ec1f-4a2d-a2b12cf36ee8; 0601ff52-51c9-72de-7dba-071d016473fd; 49739db0-2055-9a4b-fe22-027f5b7ceac0; e0e7fa88-1d3c-05f3-1cc9-cf6e08aa8294; 82b7a17e-2164-caec-90ba-2640a737897b; bda96371-0222-2919-d128-94f1e118a411; ca3e3dee-40da-b1c3-77ce-9b4640511151; 8241bab2-ab2a-228e-24ca-914a80d1cacc
                                    PIF-uuids (SRO): fef83dfe-5a02-50b6-12a3-0fed1189acaf; de48ed20-e0d2-ab4d-c2b3-7857110e0f6a; 4014506f-75ff-800b-3bde-d49196f39bf7; 29d6c11e-d149-b54a-6cf5-d41af778cd50; c064f9cb-018d-d5a3-12d1-29a6050118d8; 4dffbd1d-2bcb-1d85-b029-1bc4366ef4ad; f81b260a-88ed-2c7f-b87d-ea1bcb830e69; 5deeb719-799b-2752-a1dd-5788b94c0f21; 5d7761a3-8ebd-fb60-8568-6a7129bef180; 74943f3a-bacc-bfb3-3efa-b66423fa0604; c4b64326-3c78-c7ac-0535-22aa0e2b0e62; d2f68f7a-a32a-f84d-9162-71f18d7b35ec
                                    MTU ( RW): 1500
                                    bridge ( RO): xapi3
                                    managed ( RO): true
                                    other-config (MRW): xo:sdn-controller:of-rules: ["{"allow":true,"protocol":"IP","ipRange":"172.22.146.126/32","direction":"from/to","cookie":"0xd3d2533ed26a8151"}","{"allow":true,"protocol":"IP","ipRange":"172.22.146.119/32","direction":"from/to","cookie":"0xa9b47fab93762ad1"}","{"allow":true,"protocol":"IP","ipRange":"172.22.146.120/30","direction":"from/to","cookie":"0x20b7928056a3e208"}","{"allow":true,"protocol":"IP","ipRange":"172.22.146.124/32","direction":"from/to","cookie":"0x67d0c4dc2d9fd8a9"}","{"allow":false,"protocol":"IP","ipRange":"0.0.0.0/0","direction":"from/to","cookie":"0xd191b1374733bc1a"}"]; automatic: false
                                    blobs ( RO):
                                    tags (SRW):
                                    default-locking-mode ( RW): unlocked
                                    purpose (SRW):

                                    @semarie said:

                                    output of xe pool-list params=other-config (for xo:sdn-controller:* elements)
                                    xo:sdn-controller:of-method: xapi-plugin; xo:sdn-controller:of-format: xapi-plugin; auto_poweron: true;

                                    @semarie said:

                                    output of xe vif-list params=uuid,network-uuid,other-config (for xo:sdn-controller:* elements)

                                    this output is pointless because our current rules are on network, not on VIF anymore.

                                    bleaderB 1 Reply Last reply Reply Quote 0
                                    • bleaderB Offline
                                      bleader Vates 🪐 XCP-ng Team @andersonalipio
                                      last edited by

                                      @andersonalipio Let's continue the discussion with @semarie in a separate thread

                                      1 Reply Last reply Reply Quote 0
                                      • gduperreyG Offline
                                        gduperrey Vates 🪐 XCP-ng Team
                                        last edited by

                                        Hello,

                                        We have just made "refreshed" XCP-ng installation ISOs available for everyone; these include all updates released over the past year, up to the present day.

                                        You can read the blog post here: https://xcp-ng.org/blog/2026/08/14/xcp-ng-8-3-lts-refreshed-installation-isos/

                                        1 Reply Last reply Reply Quote 0
                                        • glehG Offline
                                          gleh Vates 🪐 XCP-ng Team @rzr
                                          last edited by stormi

                                          New maintenance update candidates for XCP-ng 8.3 LTS

                                          This release batch contains mostly fixes, tool version updates, and some improvements.

                                          What changed

                                          Virtualization & System

                                          • kernel:

                                            • Reliability fixes for CVE-2026-45840 and CVE-2026-53227.
                                            • On some systems, PCIe expansion cards connected to a hotplug-capable PCI bus might not be seen at boot time. This release fixes such systems.
                                            • Fixed CVE-2026-64600, also known as RefluXFS. By default, XCP-ng doesn’t use XFS; when an XFS SR is used, we consider the LPE risk low, but fixed it anyway as a defence-in-depth measure.
                                          • xen:

                                            • Synchronization with XenServer release 4.17.6-12:
                                              • Various XSA fixes that were already included in XCP-ng previous releases are now part of this XS release.
                                              • It also brings fixes for possible bugs and crashes.
                                            • Fix bug causing UEFI logic to set inappropriate screen resolutions.
                                          • edk2: Add XCP-ng branding to the UEFI VM boot logo

                                          • varstored and xcp-efivar-utils:

                                            • Sync with XenServer 1.3.4-2.
                                            • Group existing EFI helper scripts into a shared package xcp-efivar-utils.
                                            • Update dbx hashes from secureboot_objects v1.6.5.
                                          • xcp-emu-manager: Stability fixes for aborting live migration and pausing a migrated VM to finalize the migration.

                                          • xcp-ng-generic-lib: Fix build that was failing because of cmake3 update

                                          Control Plane

                                          • xapi:

                                            • Improve error reporting when pool join fails on TLS verification
                                            • Disallow PCI passthrough for boot devices, which would break dom0 boot
                                            • Add DHCP setting for VIF IP configuration, currently only supported by the Windows guest agent
                                            • Allow selecting image format (VHD, QCOW2) for VDIs during migration
                                            • Ensure the xapi database is flushed when shutting down
                                            • Add VLAN filtering support in XAPI.
                                            • Reuse sessions of storage backends, reducing the load on the database
                                            • Fixed cross-pool migration being blocked for VMs that couldn't be booted on the sender pool
                                            • Fixed wrong task timeout calculation for VMs with a large number of VBDs (and similar multi-part tasks)
                                          • xcp-ng-xapi-plugins:

                                            • in sdncontroller.py plugin, fix dump-flows command when calling it against VLAN interface.
                                            • in sdncontroller.py plugin, fix add-rule command in edge case (error out instead of cleanly quit).
                                          • xsconsole:

                                            • Retry the xapi connection instead of latching it broken forever
                                            • Add the option not to rename the management interface when performing an emergency network reset
                                            • Reset the old management interface IP configuration when switching to a new interface with the same IP address

                                          Storage

                                          • blktap: Fixes and log improvement

                                            • Stabilization fixes on qcow2 release:
                                              • Fix a potential deadlock on VDI export.
                                              • Fix a potential crash that could be invisible to the user because it could happen on the VDI close.
                                              • Fix a wrong VDI statistics computation.
                                            • tap-ctl commands now displays clear and parsable error messages.
                                          • sm: Storage driver performance and stability have been significantly improved (QCOW2),

                                            • Drivers improvements + perf:
                                              - Add live leaf coalesce support for QCOW2 to avoid bump in size error.
                                              - Improve performance of scan on LVMSR with QCOW2 VDIs.
                                              - Reduce read cost of FileSR VDI allocated size during scan. Speed improvement for QCOW2: x10.
                                            • Drivers misc:
                                              • Robustify drivers: they have now an internal supported image format list.
                                              • Preserve image-format field during resize on FileSR.
                                              • Fix wrong data in LVMSR MGT: always store snapshot UUID instead of OpaqueRef.
                                              • Fixed a wrongful termination of the GC when having multiple openers of chain of VHD.
                                            • LINSTOR:
                                              • Improve LINSTOR perf: don't load VDIs during VDI.deactivate call.
                                              • Fix a bad LINSTOR snap rollback caused by a journaler race condition.
                                              • Improve performance of the LINSTOR Journaler by using the existing connection to the controller to avoid re-parsing the URI.
                                              • Fix a race condition in LINSTOR SR when trying to perform a snapshot while the same VDI is currently coalescing
                                            • To help recovering from a LINSTOR database corruption, it is now backed up regularly and after every major operation, locally on the master, and on the replicated LINSTOR database device.
                                            • Upstream changes:
                                              • Ignore LVM VDI missing from VGs and XAPI: prevent abort during scan.
                                              • SCSI volumes: resolve device names correctly using canonical device path(s). Some volumes were not resolved correctly.
                                              • Explain errors when a LUN cannot be resized.
                                              • Code optimization and cleanup.
                                              • Ignore LVM VDI missing from VGs and XAPI: prevent abort during scan.
                                              • SCSI volumes: resolve device names correctly using canonical device path(s). Some volumes were not resolved correctly.
                                              • Explain errors when a LUN cannot be resized.
                                              • Code optimization and cleanup.
                                              • Improved handling of wrongful metadata stored on VDI following an error.
                                              • Robustified tapdisk pause mechanism.

                                          Regarding this sm update, please check whether the SM logs show any crashes related to the GC, particularly on NFS SRs, and send us these logs if there are any issues.

                                          Network

                                          • ca-certificates: Refresh root certificates to connect to third parties depending on Certificate Authorities.

                                          • krb5: The Kerberos 5 library has been updated to improve GSSAPI compatibility to prepare upcoming packages upgrade (and to satisfy XS-8.4 migration).

                                          • libreswan: Addressed DoS vulnerabilities (CVE-2026-12413, CVE-2026-50721, CVE-2026-50722) in encrypted Global Private Networks. Exposure appears minimal for XCP-ng environments, as OVS handles the underlying Libreswan orchestration directly.

                                          • openssh: Fix regression and apply security patches.

                                            • Custom OpenSSH configurations will now be applied (custom rules are placed in /etc/ssh/sshd_config.d/. The files must end with .conf suffix)
                                            • Five minor security flaws have been fixed in OpenSSH:
                                              • CVE-2025-32728: A logic error was fixed regarding cases where x11_forwarding is disabled.
                                              • CVE-2025-61984: Checks for forbidden characters have been tightened.
                                              • CVE-2025-61985: A specific character has been disallowed in URL-encoded strings.
                                              • CVE-2026-35385: The behavior when using scp with -O (without -p) has been corrected to prevent privilege escalation.
                                              • CVE-2026-35388: The behavior regarding "ask/autoask" or ssh -O proxy ... has been corrected.
                                          • p11-kit: - Updated library to prepare upcoming packages upgrade.

                                          UI

                                          • xo-lite: Update to 0.24.0-1
                                            • [System] Update system pages layout (user feedback) (PR #9746)

                                            • Introduce robots.txt for avoid browser indexing (PR #9858)

                                            • Update the UiTitle component to use the one from web-core (PR #9869)

                                            • [Pool/System] Add Reboot VM on internal shutdown in pool's system tab (PR #9962)

                                            • Update the UiCard component to use the one from web-core (PR #9980)

                                            • Update the UiCardTitle component to use the one from web-core (PR #9982)

                                            • Replacement of the UiSeparator component with VtsDivider from web-core (PR #10017)

                                            • Update side panels (PR #9836)

                                            • [XOA deploy] Update log visualization component (PR #9995)

                                            • [SidePanels] Add and use new VtsCardObjectTitle component to display object title and ID in side panels (PR #9755)

                                            • Replacement of the UiSpinner component with UiLoader from web-core (PR #10023)

                                            • [Pool,Host/Storage] Add Storage tabs (PR #10005)

                                            • [Host/dashboard] Switch CPU and RAM panels order to match Pool dashboard layout (PR #10059)

                                            • Remove all "coming soon" disabled button placeholders from network, VM, and pool components (PR #10068)

                                            • [VM/Network] add possibility to “connect/disconnect” a VIF on a VM (PR #10080)

                                            • [Pool/networks] Add the possibility to copy information from one or more networks in JSON format (PR #10083)

                                            • Fix some design inconsistency between pages (PR #10109)
                                              Update of the xo-lite RPM to version 0.23.0 at the request of the XO team.

                                            • [System] Update system pages layout (user feedback) (PR #9746)

                                            • Introduce robots.txt for avoid browser indexing (PR #9858)

                                            • Update the UiTitle component to use the one from web-core (PR #9869)

                                            • [Pool/System] Add Reboot VM on internal shutdown in pool's system tab (PR #9962)

                                            • Update the UiCard component to use the one from web-core (PR #9980)

                                            • Update the UiCardTitle component to use the one from web-core (PR #9982)

                                            • Replacement of the UiSeparator component with VtsDivider from web-core (PR #10017)

                                            • Update side panels (PR #9836)

                                            • [XOA deploy] Update log visualization component (PR #9995)

                                            • [SidePanels] Add and use new VtsCardObjectTitle component to display object title and ID in side panels (PR #9755)

                                            • Replacement of the UiSpinner component with UiLoader from web-core (PR #10023)

                                            • [Pool,Host/Storage] Add Storage tabs (PR #10005)

                                          Drivers and Firmware

                                          • amd-microcode: Update to 2026-05-19 drop as redistributed by XenServer. Updated CPUs:

                                            • BRH-C1 00b00f21: 2025-10-17, rev 0b002161 -> 2025-10-17, rev 0b002162
                                            • BRHD-B0 00b10f10: 2025-10-17, rev 0b101058 -> 2025-10-17, rev 0b101059
                                          • qlogic-fastlinq-alt_8_42: If encountering issue with the current driver versions (main or alt ones) on some older hardware, this alt_8_42 package is based on an older source version can be tested for better results.

                                          Others

                                          • bash: No impact on usability, just for packaging facilities
                                          • gmp: Updated library to prepare upcoming packages upgrade.
                                          • redhat-lsb: Align to XS: Drop unused sub packages
                                          • zlib: No impact on usability, just for packaging facilities

                                          Versions

                                          • amd-microcode: 20251203-1.1.xcpng8.3 -> 20260519-1.1.xcpng8.3
                                          • bash: 4.2.46-30.el7 -> 4.2.46-30.1.xcpng8.3
                                          • blktap: 3.55.5-9.1.xcpng8.3 -> 3.55.5-9.3.xcpng8.3
                                          • ca-certificates: 2021.2.50-72.el7_9 -> 2021.2.50-73.1.xcpng8.3
                                          • edk2: 20220801-1.7.11.1.xcpng8.3 -> 20220801-1.7.11.2.xcpng8.3
                                          • gmp: 6.0.0-15.el7 -> 6.2.1-8.1.xcpng8.3
                                          • gpumon: 24.1.0-91.1.xcpng8.3 -> 24.1.0-96.1.xcpng8.3
                                          • kernel: 4.19.19-8.0.46.6.xcpng8.3 -> 4.19.19-8.0.46.10.xcpng8.3
                                          • krb5: 1.15.1-22.1.xcpng8.3 -> 1.21.3-4.1.xcpng8.3
                                          • libreswan: 4.12-2.3.2.xcpng8.3 -> 4.12-2.3.3.xcpng8.3
                                          • ocaml: 4.14.2-1.xcpng8.3 -> 4.14.4-1.xcpng8.3
                                          • ocaml-findlib: 1.9.8-1.xcpng8.3 -> 1.9.8-1.1.xcpng8.3
                                          • opam: 2.4.1-1.1.xcpng8.3 -> 2.5.2-1.1.xcpng8.3
                                          • openssh: 9.8p1-1.2.4.xcpng8.3 -> 9.8p1-1.2.6.xcpng8.3
                                          • p11-kit: 0.23.5-3.el7 -> 0.24.1-4.xcpng8.3
                                          • perl-Archive-Tar: 1.92-3.el7
                                          • qlogic-fastlinq-alt_8_42: 8.42.10.0-2.xcpng8.3
                                          • redhat-lsb: 4.1-27.el7.centos.1 -> 4.1-28.2.1.xcpng8.3
                                          • sm: 3.2.12-17.9.xcpng8.3 -> 3.2.12-23.4.xcpng8.3
                                          • varstored: 1.3.2-2.1.xcpng8.3 -> 1.3.4-2.1.xcpng8.3
                                          • xapi: 26.1.11-1.3.xcpng8.3 -> 26.1.16-1.1.xcpng8.3
                                          • xcp-efivar-utils: 1.0.0-1.xcpng8.3
                                          • xcp-emu-manager: 1.2.0-2.xcpng8.3 -> 1.2.1-2.xcpng8.3
                                          • xcp-featured: 1.2.1-2.xcpng8.3 -> 1.2.1-4.xcpng8.3
                                          • xcp-ng-generic-lib: 1.1.1-4.xcpng8.3 -> 1.1.1-5.xcpng8.3
                                          • xcp-ng-xapi-plugins: 1.16.0-1.xcpng8.3 -> 1.17.0-1.xcpng8.3
                                          • xen: 4.17.6-9.3.1.xcpng8.3 -> 4.17.6-12.2.xcpng8.3
                                          • xo-lite: 0.21.0-1.xcpng8.3 -> 0.24.0-1.xcpng8.3
                                          • xs-opam-repo: 6.99.0-1.4.xcpng8.3 -> 6.99.0-1.5.xcpng8.3
                                          • xsconsole: 11.0.9.1-1.1.xcpng8.3 -> 11.0.9.1-1.3.xcpng8.3
                                          • zlib: 1.2.7-17.el7 -> 1.2.7-17.1.xcpng8.3

                                          Test on XCP-ng 8.3

                                          yum clean metadata --enablerepo=xcp-ng-testing,xcp-ng-candidates
                                          yum update --enablerepo=xcp-ng-testing,xcp-ng-candidates
                                          reboot
                                          

                                          The usual update rules apply: pool coordinator first, etc.

                                          What to test

                                          As usual, normal use and anything else you want to test.

                                          Regarding this sm update, please check whether the SM logs show any crashes related to the GC, particularly on NFS SRs, and send us these logs if there are any issues.

                                          Test window before official release of the updates

                                          ~ 4 days

                                          We would like to thank users who shared feedback since our last call for testing:

                                          @Andrew, @JeffBerntsen, @MajorP93, @TrapoSAMA, @acebmxer, @andersonalipio, @flakpyro, @marcoi

                                          M acebmxerA J B A 6 Replies Last reply Reply Quote 6
                                          • M Offline
                                            MajorP93 @gleh
                                            last edited by

                                            @gleh Wow! This sounds like a big release especially in the QCOW2 / storage department.
                                            A huge thanks to the whole XCP-ng team!
                                            The platform keeps improving and improving which is awesome to see.

                                            I will test this batch of packages next week when my test environment is available again.

                                            Best regards

                                            1 Reply Last reply Reply Quote 1

                                            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                            With your input, this post could be even better 💗

                                            Register Login
                                            • First post
                                              Last post