XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XSA-468: multiple Windows PV driver vulnerabilities - update now!

    Scheduled Pinned Locked Moved News
    65 Posts 14 Posters 3.9k Views 9 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stormiS Offline
      stormi Vates 🪐 XCP-ng Team @Andrew
      last edited by stormi

      @Andrew I've thought about it and I agree on the principle as there's already a section about guest tools there, but we have put enough pressure on the XO team to make them release the helpful features in time to help users detect vulnerable VMs, on XOA's stable update channel, so it might be wiser to wait for XO6 for such alert to be in a centralized place about guest tools.

      CC @lsouai-vates

      1 Reply Last reply Reply Quote 1
      • stormiS Offline
        stormi Vates 🪐 XCP-ng Team @stormi
        last edited by stormi

        said in XSA-468: multiple Windows PV driver vulnerabilities - update now!:

        @Tristis-Oris

        1. We do plan a way to remove the warning for VMs that you would choose.

        That's now done and will be included in the next update to the latest update channel for XOA. VMs with the HIDE_XSA468 tag will not be included in the vulnerability detection.

        1 Reply Last reply Reply Quote 1
        • G Offline
          Greg_E
          last edited by

          Better late than never I guess 🤔

          4 out of 5 of my Server 2022 VMs needed to have the networking set back to manual after the driver update. 5 out of 5 need to have the system drive marked as non-removeable, but I need to move on for a couple other things before swinging back to the system drives.

          D 1 Reply Last reply Reply Quote 0
          • D Offline
            dinhngtu Vates 🪐 XCP-ng Team @Greg_E
            last edited by

            @Greg_E Are you moving straight from older Citrix drivers or from XCP-ng drivers? XenClean 9.0.9108 and newer should now keep static IP settings on execution.

            G 1 Reply Last reply Reply Quote 0
            • G Offline
              Greg_E @dinhngtu
              last edited by

              @dinhngtu

              I went from Citrix 9.3.3 to 9.4.1, and generally they have remained manual when I've upgraded. All these VMs started out with 9.2.x so this is probably the fourth update to them.

              And all that said, I know the MAC address did not change, because I had a reservation for one of them and it was found properly before putting it back to manual. I think the XCP-ng side of things worked properly (no MAC change), but the driver side was the issue, and nothing you can fix since you don't write this driver.

              I probably should have used the cleaner first, but I went straight to the Citrix installer like I've done in the past. Took about an hour to get the 5 VMs updated, now I can move on to other things that have been lacking. I've mentioned it a few times, but this construction has me way behind for the summer, and only a few weeks of work time left before students come back.

              1 Reply Last reply Reply Quote 1
              • F Offline
                flakpyro @archw
                last edited by

                Not to bring up an old thread but was the issue of the Management agent version not properly being displayed with 9.4.1 after a migration ever figured out?

                D G 2 Replies Last reply Reply Quote 0
                • D Offline
                  dinhngtu Vates 🪐 XCP-ng Team @flakpyro
                  last edited by

                  @flakpyro It's most likely a bug in the Citrix agent.

                  1 Reply Last reply Reply Quote 1
                  • G Offline
                    Greg_E @flakpyro
                    last edited by

                    @flakpyro

                    The five I updated were all reporting properly as of last week when I looked at it last.

                    I still haven't fixed the OS drive showing as removable, I'll catch that before the August MS updates and reboot.

                    T 1 Reply Last reply Reply Quote 0
                    • T Offline
                      TrapoSAMA @Greg_E
                      last edited by

                      @Greg_E

                      I see that error only with 2022 server

                      🙂

                      G 1 Reply Last reply Reply Quote 0
                      • G Offline
                        Greg_E @TrapoSAMA
                        last edited by

                        @TrapoSAMA

                        All of mine are 2022, but saw this in previous driver versions with 2025. Low priority on this so I haven't fixed it yet.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post