Recent content by ProxmoxSecurityAdvisory

  1. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00023-1: LXC config injection / local privilege escalation via env property Advisory date: 2026-05-21 Packages: pve-container since 6.0.19 Details: Incomplete validation of the env property value in the pve-container LXC config handling code allowed injection of arbitrary...
  2. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00022-1: "pintheft" local privilege escalation Advisory date: 2026-05-19 Packages: proxmox-kernel-* Details: A double-free bug in the RDS network handling code of the Linux kernel was discovered, which could be combined with an IO_URING page cache overwrite to achieve local...
  3. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00021-1: "ssh-keysign-pwn" file disclosure via setuid binaries Advisory date: 2026-05-18 Packages: proxmox-kernel-* Details: A flaw in the Linux kernel was discovered that allowed a local, unprivileged user to exploit a race during the process exit of a setuid binary...
  4. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00020-1: "Fragnesia" local privilege escalation Advisory date: 2026-05-18 Packages: proxmox-kernel-* Details: Incomplete tracking of whether a network packet (fragment) is externally backed (for example by user-/attacker-provided pages from the page cache) could be...
  5. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00019-2: "DirtyFrag" Local Privilege Escalation Advisory date: 2026-05-08 Packages: proxmox-kernel-* Details: Two vulnerabilities in the Linux kernel were discovered, which when combined, allow an unprivileged local user to obtain root privileges. Mitigation: See...
  6. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00019-1: "DirtyFrag" Local Privilege Escalation Advisory date: 2026-05-08 Packages: proxmox-kernel-* Details: Two vulnerabilities in the Linux kernel were discovered, which when combined, allow an unprivileged local user to obtain root privileges. Mitigation: Until fixed...
  7. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00018-1: "copy.fail" local privilege escalation via AF_ALG socket Advisory date: 2026-04-30 Packages: proxmox-kernel-6.8, proxmox-kernel-6.14, proxmox-kernel-6.17 Details: An issue published under the name "copy.fail" was found in the Linux kernel's handling of AF_ALG...
  8. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00017-1: Missing redaction of cloudinit cipassword in cloudinit/dump endpoint Advisory date: 2026-04-24 Packages: qemu-server Details: The endpoint used for provisioning cloud-init configuration correctly masks the cipassword field when returning the configuration. The...
  9. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00016-1: Stored XSS in VM notes field Advisory date: 2026-04-24 Packages: pve-manager, proxmox-yew-comp, proxmox-datacenter-manager-ui Details: Missing sanitation of the <base> HTML tag when encoding the VM notes field could be exploited to execute arbitrary JS code in the...
  10. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00015-1: Missing HA permission checks when auto-adding guest on create/restore Advisory date: 2026-04-24 Packages: qemu-server >= 9.0.24, pve-container >= 6.0.14 (PVE 9.x) Details: When creating or restoring a VM or container, it was possible to automatically add the...
  11. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00014-1: Multiple VNC related issues Advisory date: 2026-04-24 Packages: qemu-server, pve-manager, pve-container Details: A race condition between the vncproxy and vncwebsocket API calls allowed an attacker with privileges to call "vncproxy" to hijack a VNC session that is...
  12. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00013-1: OVA import XML XXE file disclosure and server-side request forgery Advisory date: 2026-04-24 Packages: pve-storage Details: If a storage with 'import' content type was available as upload/download target, a malicious archive could be used to leak arbitrary file...
  13. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00012-1: Corosync: DoS via malformed packets in unencrypted clusters Advisory date: 2026-04-15 Packages: corosync Details: Two flaws were found in Corosync, the clustering stack backing Proxmox VE's clustering feature. An integer overflow vulnerability in Corosync's join...
  14. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00011-1: too permissive pmxcfs backup permissions Advisory date: 2026-04-08 Packages: pve-cluster Details: The pmxcfs backup created before joining a cluster was stored in a directory that was world-readable. Depending on which configuration steps were done before joining...
  15. ProxmoxSecurityAdvisory

    Proxmox Datacenter Manager - Security Advisories

    Subject: PSA-2026-00010-1: "Crackarmor" apparmor vulnerabilities Advisory date: 2026-03-13 Packages: proxmox-kernel-* Details: Qualys discovered several vulnerabilities in the AppArmor LSM (Linux Security Module) code of the Linux kernel, which are being referred to as "Crackarmor". All of...