That service is currently used to transfer a VM’s connection-tracking state during live migration, so established connections (within the guest) continue to be recognized by stateful firewalls on the target node.
The stale object should not be...
Hi,
what is the purpose of the pve-dbus-vmstate@.service?
It starts a Perl script /usr/libexec/qemu-server/dbus-vmstate but not for every VM.
We have seen it running for a few VMs and sometimes it fails:
Aug 31 15:17:22 pve56 systemd[1]...
Then you are still vulnerable due to the known and unknown security issues in PVE8 (which is EOL) and Debian Bookworm. The fix is to upgrade to the latest supported version of PVE aka PVE9 with every updated installed. Everything else is just...
So, you now got your security advisory for a vulnerability, in a over three year old version of a software component, which was at the time it would have been relevant neither internally discovered nor from anyone reported and hopefully also not...
Der Lizenz-Punkt von @Johannes S ist eigentlich der spannendere, das Codestyle-Argument erledigt sich ja mit genug Nachdruck im Review. Beim DCO unterschreibst du nicht nur "ich steh dafür grade", sondern auch dass du das Recht hast, den Code...
Du hast "Das Geschäftsmodell der AI-Codeassistenten beruht auf systematischen Verstoßen gegen Urheberrecht und opensource-Lizenzen" sehr umständlich ausgedrückt :)
Weil auch wenn das Problem nicht grundsätzlich neu ist, erreicht es so doch eine...
Ich sehe ( und das als bekennender KI-Luddit!) auch nicht so das Problem. Im Grunde sagt Debian, dass „aber die ki sagt, das passt so“ keine erlaubte Ausrede ist Bullshit abzuliefern ;)
OpenBSD hatte ja das Vergnügen mit einen Vibecoder, der...
Ehrlich gesagt ändert das bei Debian doch wenig, mit dem DCO lag die Verantwortung schon immer beim Einreicher. Ungeprüft zusammenkopierten Kram gab's auch vorher schon, halt von Stack Overflow statt vom LLM. Was real schützt ist der Review- und...
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed...
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...
The Linux kernel has had at least 500 CVE's fixed per release (before LLMs) and your PVE 7 kernel (5.15?) is many version behind, so either one could potentially be the entry point. Whether you had a good password is irrelevant. Proxmox fixed...
PVE 7 and the Debian version it sits on went end of life over two (corrected from three) years ago. The list of vulnerabilities discovered and patched since then is going to be a mile long.
It would even be a bad idea to expose a fully patched...
Thank you for reminding people to regularly upgrade their software (and not run unsupported versions). I do hope you can recover from backups on a fresh (and supported) Proxmox.
There is a section in the PBS manual about ransomware...
In a PVE-cluster, there is no master node or something like that.
Just move all guests to the other nodes and power that node off. Wait a few minutes and if nothing explodes, move on with your reinstallation... ;)
I ran into the same warning after upgrading from PVE 8 to PVE 9 with Ceph Squid.
It looks like /etc/init.d/ceph is simply an obsolete conffile left behind by ceph-base:
# dpkg -S /etc/init.d/ceph
ceph-base: /etc/init.d/ceph
# dpkg-query -W...