Subject: PSA-2026-00042-1: missing privilege checks for vzdump stop API calls
Advisory date: 2026-08-17
Packages: pve-manager
Details:
Any authenticated user/API token could trigger a stop of running backups.
This issue was reported...
Subject: PSA-2026-00038-1: TONTOU kernel memory leak via branch predictor re-poisoning
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A new technique to leak kernel memory despite spectre v2 mitigations being in place to...
Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernels SCTP code allowed a unprivileged local attacker to obtain root...
Subject: PSA-2026-00036-1: "Zapscape" KVM guest to host escape on x86_64
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A use-after-free issue was discovered in the Linux kernel's KVM module's shadow MMU code. On hosts with...
Subject: PSA-2026-00035-1: missing privilege checks for container start-after-create/start-after-rollback
Advisory date: 2026-08-03
Packages: pve-container
Details:
When creating a container or triggering a rollback to a snapshot, the...
Subject: PSA-2026-00034-1: missing validation of comment field in firewall API
Advisory date: 2026-08-03
Packages: pve-firewall, proxmox-firewall
Details:
Missing validation of the comment field in the firewall API allowed an authenticated...
Subject: PSA-2026-00033-1: Authenticated Remote Code Execution via custom_check_path setting
Advisory date: 2026-08-03
Packages: pmg-api
Details:
The custom_check_path setting could be set by any user with 'Administrator' role. This script is...
Subject: PSA-2026-00032-1: "OVSWrap" local privilege escalation issue in OpenVSwitch
Advisory date: 2026-07-29
Packages: proxmox-kernel-*
Details:
Two issues found in the Linux kernel's openvswitch module were discovered which allow leaking...
Subject: PSA-2026-00031-1: Several vulnerabilities found in the Linux kernel
Advisory date: 2026-07-20
Packages: proxmox-kernel-6.17
Details:
Various issues with security implications were discovered in the Linux kernel.
Fixed in:
-...
Subject: PSA-2026-00030-1: Several vulnerabilities found in the Linux kernel
Advisory date: 2026-07-20
Packages: proxmox-kernel-6.8
Details:
Various issues with security implications were discovered in the Linux kernel.
Fixed in:
-...
Subject: PSA-2026-00029-1: overflow in ipv6 fragmentation code
Advisory date: 2026-07-20
Packages: proxmox-kernel-*
Details:
An in-slab linear overflow issue was discovered in the Linux kernel's IPv6 fragementation code. This issue could be...
Subject: PSA-2026-00028-1: "IonStack"/"GhostLock" use after free vulnerability in the Linux kernel
Advisory date: 2026-07-20
Packages: proxmox-kernel-*
Details:
A Use-After-Free issue in the kernel's rtmutex/futex-PI code allows an attacker...
Subject: PSA-2026-00027-1: Januscape: Guest-to-Host Escape in KVM/x86
Advisory date: 2026-07-08
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernel's handling of shadow MMU emulation in KVM allows an attacker inside...
Subject: PSA-2026-00026-1: "Bad Epoll" Local Privilege Escalation kernel issue
Advisory date: 2026-07-08
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernel's epoll subsystem was discovered, allowing an unprivileged...
Subject: PSA-2026-00025-1: Several vulnerabilities found in the Linux kernel
Advisory date: 2026-06-01
Packages: proxmox-kernel-*
Details:
Several vulnerabilities affecting the apparmor and network generic receive offload code in the Linux...
Subject: PSA-2026-00024-1: "CIFSwitch" local privilege escalation
Advisory date: 2026-05-29
Packages: proxmox-kernel-*
Details:
Missing validation of the cifs.spnego key object in the Linux kernel could be exploited by a local, unprivileged...
Subject: PSA-2026-00022-2: "pintheft" local privilege escalation
Advisory date: 2026-05-29
Packages: proxmox-kernel-*
Details:
A double-free bug in the RDS network handling code of the Linux kernel was discovered, which could be combined with...