Recent content by ProxmoxSecurityAdvisory

  1. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00035-1: missing privilege checks for container start-after-create/start-after-rollback Advisory date: 2026-08-03 Packages: pve-container Details: When creating a container or triggering a rollback to a snapshot, the VM.PowerMgmt privilege was not checked correctly if the...
  2. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00034-1: missing validation of comment field in firewall API Advisory date: 2026-08-03 Packages: pve-firewall, proxmox-firewall Details: Missing validation of the comment field in the firewall API allowed an authenticated attacker with privileges to modify at least one...
  3. ProxmoxSecurityAdvisory

    Proxmox Mail Gateway - Security Advisories

    Subject: PSA-2026-00033-1: Authenticated Remote Code Execution via custom_check_path setting Advisory date: 2026-08-03 Packages: pmg-api Details: The custom_check_path setting could be set by any user with 'Administrator' role. This script is executed for every mail received, with the path...
  4. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00032-1: "OVSWrap" local privilege escalation issue in OpenVSwitch Advisory date: 2026-07-29 Packages: proxmox-kernel-* Details: Two issues found in the Linux kernel's openvswitch module were discovered which allow leaking kernel addresses and decrementing arbitrary kernel...
  5. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00031-1: Several vulnerabilities found in the Linux kernel Advisory date: 2026-07-20 Packages: proxmox-kernel-6.17 Details: Various issues with security implications were discovered in the Linux kernel. Fixed in: - proxmox-kernel-6.17.13-18-pve(-signed) (Trixie based...
  6. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00030-1: Several vulnerabilities found in the Linux kernel Advisory date: 2026-07-20 Packages: proxmox-kernel-6.8 Details: Various issues with security implications were discovered in the Linux kernel. Fixed in: - proxmox-kernel-6.8.12-36-pve(-signed) (Bookworm based...
  7. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00029-1: overflow in ipv6 fragmentation code Advisory date: 2026-07-20 Packages: proxmox-kernel-* Details: An in-slab linear overflow issue was discovered in the Linux kernel's IPv6 fragementation code. This issue could be used to obtain root privileges as a local...
  8. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00028-1: "IonStack"/"GhostLock" use after free vulnerability in the Linux kernel Advisory date: 2026-07-20 Packages: proxmox-kernel-* Details: A Use-After-Free issue in the kernel's rtmutex/futex-PI code allows an attacker to write to arbitrary addresses. This can be used...
  9. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00027-1: Januscape: Guest-to-Host Escape in KVM/x86 Advisory date: 2026-07-08 Packages: proxmox-kernel-* Details: A use-after-free issue in the Linux kernel's handling of shadow MMU emulation in KVM allows an attacker inside a VM with nested KVM enabled to escape from the...
  10. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00026-1: "Bad Epoll" Local Privilege Escalation kernel issue Advisory date: 2026-07-08 Packages: proxmox-kernel-* Details: A use-after-free issue in the Linux kernel's epoll subsystem was discovered, allowing an unprivileged local attacker to gain root privileges. Fixed...
  11. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00025-1: Several vulnerabilities found in the Linux kernel Advisory date: 2026-06-01 Packages: proxmox-kernel-* Details: Several vulnerabilities affecting the apparmor and network generic receive offload code in the Linux kernel were found, allowing denial of service or...
  12. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00024-1: "CIFSwitch" local privilege escalation Advisory date: 2026-05-29 Packages: proxmox-kernel-* Details: Missing validation of the cifs.spnego key object in the Linux kernel could be exploited by a local, unprivileged attacker to obtain root privileges. Mitigations...
  13. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00022-2: "pintheft" local privilege escalation Advisory date: 2026-05-29 Packages: proxmox-kernel-* Details: A double-free bug in the RDS network handling code of the Linux kernel was discovered, which could be combined with an IO_URING page cache overwrite to achieve local...
  14. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00023-1: LXC config injection / local privilege escalation via env property Advisory date: 2026-05-21 Packages: pve-container since 6.0.19 Details: Incomplete validation of the env property value in the pve-container LXC config handling code allowed injection of arbitrary...
  15. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00022-1: "pintheft" local privilege escalation Advisory date: 2026-05-19 Packages: proxmox-kernel-* Details: A double-free bug in the RDS network handling code of the Linux kernel was discovered, which could be combined with an IO_URING page cache overwrite to achieve local...