XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Home
    2. rvreugde
    3. Topics
    Offline
    • Profile
    • Following 0
    • Followers 0
    • Topics 6
    • Posts 28
    • Groups 0

    Topics

    • rvreugdeR

      XOA vulnerabilty to "copy fail" and "dirty frag" bug

      Watching Ignoring Scheduled Pinned Locked Moved XCP-ng
      8
      0 Votes
      8 Posts
      605 Views
      R
      Quick update now that Vates has published their official advisory. First, kudos to the Vates security team for the thorough and timely response. VSA-2026-014 is well-documented and covers the full picture, including a third CVE I had not covered in my earlier posts. VSA-2026-014 confirms what I outlined above: XCP-ng is affected by CVE-2026-43284 (XFRM-ESP) and is NOT affected by CVE-2026-43500 (no RxRPC support). The CVE I had missed: CVE-2026-46300 ("Fragnesia") also affects XCP-ng via the XFRM ESP-in-TCP subsystem. The same esp4/esp6 blacklist mitigation applies, with the same caveat @semarie raised: it will break encrypted private networks on XCP-ng. Now that the VSA and official mitigation guidance are public, I'm releasing the diagnostic script I built. It's Python 3.6, no external dependencies, safe to run on production dom0. It tests whether an unprivileged process can engage the esp4 engine via the XFRM interface inside a user namespace — without touching any exploit code. Since both CVE-2026-43284 and CVE-2026-46300 (Fragnesia) require esp4 or esp6 to be reachable from an unprivileged namespace, and share the same mitigation, a positive result confirms exposure to both. Blacklist esp4/esp6, then run the script again — ACCESS DENIED means both CVEs are mitigated. One important note before running it: please read the code before executing it on any of your systems. This is good practice with any script from the internet, regardless of the source. The code is intentionally short and straightforward so you can review it quickly and satisfy yourself that it does exactly what it says. VSA-2026-014: https://docs.vates.tech/security/advisories/2026/vates-sa-2026-014/ Diagnostic tool: https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester A kernel patch from Vates is in progress. Apply as soon as it lands.
    • rvreugdeR

      Patching XCP-ng via XOA

      Watching Ignoring Scheduled Pinned Locked Moved Management
      21
      3
      0 Votes
      21 Posts
      4k Views
      gthvn1G
      @olivierlambert do you know who on XOA side can have a look?
    • rvreugdeR

      No Windows Server 2025 template availabe in XOA 5.103.1

      Watching Ignoring Scheduled Pinned Locked Moved Solved Management
      3
      1
      0 Votes
      3 Posts
      528 Views
      rvreugdeR
      This works fine, indeed. Thanks!
    • rvreugdeR

      Can not start VM migration to other pool from XOA

      Watching Ignoring Scheduled Pinned Locked Moved Management
      15
      1
      0 Votes
      15 Posts
      2k Views
      olivierlambertO
      The issue is there's a VDI that's not in the right map. It's hard to tell why without having a deeper look.
    • rvreugdeR

      Advanced telemetry enabled, fix used, but not working

      Watching Ignoring Scheduled Pinned Locked Moved Advanced features
      3
      0 Votes
      3 Posts
      492 Views
      rvreugdeR
      Thanks, this works!
    • rvreugdeR

      Moving vm in pool fails with "HOST_NOT_ENOUGH_FREE_MEMORY" (there is enough memory)!

      Watching Ignoring Scheduled Pinned Locked Moved Management
      7
      0 Votes
      7 Posts
      825 Views
      rvreugdeR
      Since it was somewhat critical (urgent migration from other pool), I had to switch the pool masters and had to restart the xcp028. But I downloaded the system log. Maybe you find the cause of the problem there? BTW, before restarting the host, I was not able to download these logs (failed).