Subject: PSA-2026-00046-1: Privilege escalation through malicious OCI container image
Advisory date: 2026-09-10
Packages: pve-container
Details:
The check for control characters in the configuration keys of OCI container images was too...
Subject: PSA-2026-00045-1: ACME directory ToS URL XSS
Advisory date: 2026-09-10
Packages: proxmox-backup, proxmox-widget-toolkit
Details:
The terms of service URL returned by an ACME directory was not escaped properly when displaying it on...
Subject: PSA-2026-00043-1: Authentication bypass in EOL Proxmox VE 7 release
Advisory date: 2026-09-01
Packages: libpve-access-control
Affected: libpve-access-control >= 7.0-7 and < 8.0.4
Roughly corresponding to Proxmox VE 7.0 up to and...
Subject: PSA-2026-00042-1: missing privilege checks for vzdump stop API calls
Advisory date: 2026-08-17
Packages: pve-manager
Details:
Any authenticated user/API token could trigger a stop of running backups.
This issue was reported...
Subject: PSA-2026-00038-1: TONTOU kernel memory leak via branch predictor re-poisoning
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A new technique to leak kernel memory despite spectre v2 mitigations being in place to...
Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernels SCTP code allowed a unprivileged local attacker to obtain root...
Subject: PSA-2026-00036-1: "Zapscape" KVM guest to host escape on x86_64
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A use-after-free issue was discovered in the Linux kernel's KVM module's shadow MMU code. On hosts with...
Subject: PSA-2026-00035-1: missing privilege checks for container start-after-create/start-after-rollback
Advisory date: 2026-08-03
Packages: pve-container
Details:
When creating a container or triggering a rollback to a snapshot, the...
Subject: PSA-2026-00034-1: missing validation of comment field in firewall API
Advisory date: 2026-08-03
Packages: pve-firewall, proxmox-firewall
Details:
Missing validation of the comment field in the firewall API allowed an authenticated...
Subject: PSA-2026-00033-1: Authenticated Remote Code Execution via custom_check_path setting
Advisory date: 2026-08-03
Packages: pmg-api
Details:
The custom_check_path setting could be set by any user with 'Administrator' role. This script is...
Subject: PSA-2026-00032-1: "OVSWrap" local privilege escalation issue in OpenVSwitch
Advisory date: 2026-07-29
Packages: proxmox-kernel-*
Details:
Two issues found in the Linux kernel's openvswitch module were discovered which allow leaking...
Subject: PSA-2026-00031-1: Several vulnerabilities found in the Linux kernel
Advisory date: 2026-07-20
Packages: proxmox-kernel-6.17
Details:
Various issues with security implications were discovered in the Linux kernel.
Fixed in:
-...
Subject: PSA-2026-00030-1: Several vulnerabilities found in the Linux kernel
Advisory date: 2026-07-20
Packages: proxmox-kernel-6.8
Details:
Various issues with security implications were discovered in the Linux kernel.
Fixed in:
-...
Subject: PSA-2026-00029-1: overflow in ipv6 fragmentation code
Advisory date: 2026-07-20
Packages: proxmox-kernel-*
Details:
An in-slab linear overflow issue was discovered in the Linux kernel's IPv6 fragementation code. This issue could be...
Subject: PSA-2026-00028-1: "IonStack"/"GhostLock" use after free vulnerability in the Linux kernel
Advisory date: 2026-07-20
Packages: proxmox-kernel-*
Details:
A Use-After-Free issue in the kernel's rtmutex/futex-PI code allows an attacker...
Subject: PSA-2026-00027-1: Januscape: Guest-to-Host Escape in KVM/x86
Advisory date: 2026-07-08
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernel's handling of shadow MMU emulation in KVM allows an attacker inside...