PT-2024-6570 · Citrix+3 · Citrix Hypervisor 8.2 Cu1+4

Published

2024-09-24

·

Updated

2025-11-09

·

CVE-2024-45817

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Xen (affected versions not specified) XenServer 8 Citrix Hypervisor 8.2 CU1
Description: The issue is related to the x86's APIC architecture, where error conditions are reported in a status register. The OS can opt to receive an interrupt when a new error occurs. It is possible to configure the error interrupt with an illegal vector, which generates an error when an error interrupt is raised. This case causes Xen to recurse through vlapic error(). The recursion itself is bounded; errors accumulate in the status register and only generate an interrupt when a new status bit becomes set. However, the lock protecting this state in Xen will try to be taken recursively, and deadlock. A malicious guest admin could exploit this issue to crash the host.
Recommendations: As a temporary workaround, consider disabling the vlapic error() function until a patch is available. Apply the available updates for XenServer 8 and Citrix Hypervisor 8.2 CU1 to protect your systems. Restrict access to the vulnerable vlapic error() function to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-07714
CVE-2024-45817
DSA-5836-1
MGASA-2025-0270
OPENSUSE-SU-2024:14377-1
OPENSUSE-SU-2024_3421-1
OPENSUSE-SU-2024_3422-1
OPENSUSE-SU-2024_3423-1
OPENSUSE-SU-2024_3424-1
OPENSUSE-SU-2024_3980-1
OPENSUSE-SU-2024_4163-1
SUSE-SU-2024:3421-1
SUSE-SU-2024:3422-1
SUSE-SU-2024:3423-1
SUSE-SU-2024:3424-1
SUSE-SU-2024:3432-1
SUSE-SU-2024:3586-1
SUSE-SU-2024:3980-1
SUSE-SU-2024:4073-1
SUSE-SU-2024:4163-1
SUSE-SU-2024_3421-1
SUSE-SU-2024_3424-1
SUSE-SU-2024_3432-1
SUSE-SU-2024_3980-1
SUSE-SU-2024_4073-1
SUSE-SU-2024_4163-1

Affected Products

Citrix Hypervisor 8.2 Cu1
Debian
Red Os
Suse
Xenserver 8