Subject: PSA-2026-00023-1: LXC config injection / local privilege escalation via env property
Advisory date: 2026-05-21
Packages: pve-container since 6.0.19
Details:
Incomplete validation of the env property value in the pve-container LXC...
Subject: PSA-2026-00022-1: "pintheft" local privilege escalation
Advisory date: 2026-05-19
Packages: proxmox-kernel-*
Details:
A double-free bug in the RDS network handling code of the Linux kernel was discovered, which could be combined with...
Subject: PSA-2026-00021-1: "ssh-keysign-pwn" file disclosure via setuid binaries
Advisory date: 2026-05-18
Packages: proxmox-kernel-*
Details:
A flaw in the Linux kernel was discovered that allowed a local, unprivileged user to exploit a race...
Subject: PSA-2026-00019-2: "DirtyFrag" Local Privilege Escalation
Advisory date: 2026-05-08
Packages: proxmox-kernel-*
Details:
Two vulnerabilities in the Linux kernel were discovered, which when combined, allow an unprivileged local user to...
Subject: PSA-2026-00019-1: "DirtyFrag" Local Privilege Escalation
Advisory date: 2026-05-08
Packages: proxmox-kernel-*
Details:
Two vulnerabilities in the Linux kernel were discovered, which when combined, allow an unprivileged local user to...
Subject: PSA-2026-00018-1: "copy.fail" local privilege escalation via AF_ALG socket
Advisory date: 2026-04-30
Packages: proxmox-kernel-6.8, proxmox-kernel-6.14, proxmox-kernel-6.17
Details:
An issue published under the name "copy.fail" was...
Subject: PSA-2026-00016-1: Stored XSS in VM notes field
Advisory date: 2026-04-24
Packages: pve-manager, proxmox-yew-comp, proxmox-datacenter-manager-ui
Details:
Missing sanitation of the <base> HTML tag when encoding the VM notes field could...
Subject: PSA-2026-00015-1: Missing HA permission checks when auto-adding guest on create/restore
Advisory date: 2026-04-24
Packages: qemu-server >= 9.0.24, pve-container >= 6.0.14 (PVE 9.x)
Details:
When creating or restoring a VM or...
Subject: PSA-2026-00014-1: Multiple VNC related issues
Advisory date: 2026-04-24
Packages: qemu-server, pve-manager, pve-container
Details:
A race condition between the vncproxy and vncwebsocket API calls allowed an attacker with privileges...
Subject: PSA-2026-00013-1: OVA import XML XXE file disclosure and server-side request forgery
Advisory date: 2026-04-24
Packages: pve-storage
Details:
If a storage with 'import' content type was available as upload/download target, a...
Subject: PSA-2026-00012-1: Corosync: DoS via malformed packets in unencrypted clusters
Advisory date: 2026-04-15
Packages: corosync
Details:
Two flaws were found in Corosync, the clustering stack backing Proxmox VE's clustering feature.
An...
Subject: PSA-2026-00011-1: too permissive pmxcfs backup permissions
Advisory date: 2026-04-08
Packages: pve-cluster
Details:
The pmxcfs backup created before joining a cluster was stored in a directory that was world-readable. Depending on...
Subject: PSA-2026-00010-1: "Crackarmor" apparmor vulnerabilities
Advisory date: 2026-03-13
Packages: proxmox-kernel-*
Details:
Qualys discovered several vulnerabilities in the AppArmor LSM (Linux Security Module) code of the Linux kernel...
Subject: PSA-2026-00010-1: "Crackarmor" apparmor vulnerabilities
Advisory date: 2026-03-13
Packages: proxmox-kernel-*
Details:
Qualys discovered several vulnerabilities in the AppArmor LSM (Linux Security Module) code of the Linux kernel...
Subject: PSA-2026-00010-1: "Crackarmor" apparmor vulnerabilities
Advisory date: 2026-03-13
Packages: proxmox-kernel-*
Details:
Qualys discovered several vulnerabilities in the AppArmor LSM (Linux Security Module) code of the Linux kernel...
Subject: PSA-2026-00010-1: "Crackarmor" apparmor vulnerabilities
Advisory date: 2026-03-13
Packages: proxmox-kernel-*
Details:
Qualys discovered several vulnerabilities in the AppArmor LSM (Linux Security Module) code of the Linux kernel...
Subject: PSA-2026-00009-1: Log poisoning via crafted HTTP Forwarded header
Advisory date: 2026-03-03
Packages: proxmox-backup-server
Details:
Clients could inject arbitrary IP addresses into Proxmox Backup Server authentication logs by adding...
Subject: PSA-2026-00008-1: User Enumeration Vulnerability in Proxmox Backup Server API Token Authentication
Advisory date: 2026-03-03
Packages: proxmox-backup-server
Details:
Different user-facing error messages were returned in case of an...