This release batch contains a security update for Xen. This update also brings a fix for a XAPI regression causing VBD leaks. Other minor changes were needed to build an updated XCP-ng 8.3 LTS installer (ISO).
Multiple Xen Security Advisories have been published since the last update. Several of them affect XCP-ng to varying degrees, and the rest are included for transparency but are assessed as not impacting our products. See the references below each section for full details.
The following vulnerabilities are fixed by this update:
Three of them are deemed to have a low impact or not exploitable in the supported use cases of XCP-ng:
Not impacting XCP-ng 8.3 LTS:
References: VSA-2026-024 ( XSA-495 , XSA-496 , XSA-508 )
XAPI is XCP-ng's control plane, it is updated to 26.1.11-1.3 and includes the following fix:
A regression was introduced to the VM.revert operation in xapi-26.1.4-3.3 , which left VBDs attached to the VM when they are not present in the reverted-to snapshot (instead of destroying such VBDs, as done before). As explained in XCP-ng documentation, systems affected by orphaned VBDs can be identified by running xapi_leaked_vbds.py script then the administrator can manually remove them accordingly.
Along with David Morel
For years Philippe has worked as a software engineer, though his involvement in software communities dates back to his teenage Amiga days. Recently he joined VATES to work on the XCP-ng virtualization platform built on the Xen Project.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
