VSA-2026-034: PoD doesn't try to reclaim special pages (CVE-2026-62434 / XSA-507)
2026-07-28 / Important severity / XCP-ng 8.3 affected.
VSA-2026-033: incorrect buffer checks for DM_OP hypercalls (CVE-2026-62433 / XSA-506)
2026-07-28 / Low severity / XCP-ng 8.3 affected.
VSA-2026-032: evtchn race between FIFO expand and reset (CVE-2026-62432 / XSA-505)
2026-07-28 / Important severity / XCP-ng 8.3 affected.
VSA-2026-031: Viridian STIMER division by zero (CVE-2026-62431 / XSA-504)
2026-07-28 / Important severity / XCP-ng 8.3 affected.
VSA-2026-030: out-of-bounds read in vRTC emulation (CVE-2026-62430 / XSA-503)
2026-07-28 / Moderate severity / XCP-ng 8.3 affected.
VSA-2026-029: vNUMA domain cleanup may race other operations (CVE-2026-62429 / XSA-502)
2026-07-28 / Low severity / XCP-ng 8.3 affected.
VSA-2026-028: grant-table version change racing with other operations (CVE-2026-62435, CVE-2026-62436 / XSA-501)
2026-07-28 / Important severity / XCP-ng 8.3 affected.
VSA-2026-027: grant-table type confusion in grant-copy (CVE-2026-62428 / XSA-500)
2026-07-28 / Critical severity / XCP-ng 8.3 affected.
VSA-2026-026: sysctl and platform-op locks open to abuse (CVE-2026-62426, CVE-2026-62427 / XSA-499)
2026-07-28 / Low severity / XCP-ng 8.3 affected.
VSA-2026-025: buffer overruns in libfsimage iso9660 handling (CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425 / XSA-497)
2026-07-28 / Moderate severity / XCP-ng 8.3 affected.
VSA-2026-024: Multiple Xen XSAs assessed as not impacting Vates products
2026-07-28 / Not applicable / Multiple XSAs assessed as not impacting Vates products.
VSA-2026-023: XAPI Missing TLS verification in some SDKs (CVE-2026-42491 / XSA-498)
2026-07-15 / Not applicable / SDK not directly used by XCP-ng.
VSA-2026-022: LLDPD vulnerability in VLAN decapsulation
2026-06-23 / Low severity / XCP-ng 8.3 affected.
VSA-2026-021: Linux Kernel CIFS Client Local Privilege Escalation (CVE-2026-46243)
2026-06-10 / Moderate severity / XCP-ng and XOA affected.
VSA-2026-020: x86 mismatched mapcache metadata (XSA-494)
2026-06-10 / Not applicable / Only affects PV guests.
VSA-2026-019: Arm TLBI completion issue (XSA-493)
2026-06-10 / Not applicable / Arm-only vulnerability.
VSA-2026-018: domctl lock open to abuse (XSA-492)
2026-06-10 / Low severity / XCP-ng 8.3 affected.
VSA-2026-017: x86 HVM I/O port list traversal (XSA-491)
2026-06-10 / Low severity / XCP-ng 8.3 affected.
VSA-2026-016: Linux Kernel ptrace and RDS Local Privilege Escalation (CVE-2026-46333, CVE-2026-43494)
2026-06-02 / Moderate severity / XCP-ng and XOA affected.
VSA-2026-015: x86 CPU Opcode Cache corruption (XSA-490)
2026-05-21 / Critical severity / XCP-ng 8.3 affected
VSA-2026-014: Linux Kernel XFRM/RXRPC Local Privilege Escalation (CVE-2026-43284, CVE-2026-43500, CVE-2026-46300)
2026-05-15 / Moderate severity / XCP-ng and XOA affected.
VSA-2026-013: Copy Fail - Linux Kernel Privilege Escalation (CVE-2026-31431)
2026-05-04 / Moderate severity / XCP-ng and XOA affected.
VSA-2026-012: Vulnerability in XCP-ng Windows Guest Tools
2026-05-05 / Low severity / XCP-ng Windows Guest Tools affected.
VSA-2026-011: Multiple XAPI potential Vulnerabilities
2026-04-28 / Low severity / 8.3 affected.
VSA-2026-010: Floating Point Divider State Sampling on AMD CPUs
2026-04-28 / Moderate severity / XCP-ng 8.3 affected.
VSA-2026-009: OpenSSH ECDSA & CA vulnerabilities
2026-04-28 / Moderate severity / XCP-ng 8.3 affected.
VSA-2026-008: XSA-486
2026-04-28 / Critical severity / XCP-ng 8.3 affected.
VSA-2026-007: XSA-483
2026-04-28 / Critical severity / XCP-ng 8.3 affected.
VSA-2026-006: Issue with scrubbing of physmap allocated pages
2026-03-24 / Important severity / XCP-ng 8.3 affected.
VSA-2026-005: XSA-480
2026-03-17 / Critical severity / XCP-ng 8.3 affected.
VSA-2026-004: Node-Tar
2026-01-29 / Low severity / XO is affected.
VSA-2026-003: XSA-479
2026-01-27 / Important severity / XCP-ng 8.3 affected.
VSA-2026-002: XSA-478
2026-01-27 / Critical severity / XCP-ng 8.3 affected.
VSA-2026-001: XSA-477
2026-01-27 / Low severity / XCP-ng 8.3 affected.