Recent content by ProxmoxSecurityAdvisory

  1. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00042-1: missing privilege checks for vzdump stop API calls Advisory date: 2026-08-17 Packages: pve-manager Details: Any authenticated user/API token could trigger a stop of running backups. This issue was reported privately by Geoffrey McClinsey...
  2. ProxmoxSecurityAdvisory

    Proxmox Backup Server - Security Advisories

    Subject: PSA-2026-00041-1: missing filename reference validation in backup manifests Advisory date: 2026-08-13 Packages: proxmox-backup-server Details: Missing validation of a backup manifest's archive/blob filename references allowed a malicious pull source to trigger reads or writes of...
  3. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00040-1: incomplete privilege checks for unused volumes Advisory date: 2026-08-12 Packages: qemu-server, pve-container Details: Incomplete privilege checks when adding an unused volume to a guest allowed accessing volumes that were out of scope for the user/API token adding...
  4. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00039-1: missing parameter validation in remote migration Advisory date: 2026-08-12 Packages: qemu-server Details: Missing parameter validation in Proxmox VE's remote migration code allowed an attacker with Sys.Incoming privileges to inject arbitrary values in parts of the...
  5. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00038-1: TONTOU kernel memory leak via branch predictor re-poisoning Advisory date: 2026-08-10 Packages: proxmox-kernel-* Details: A new technique to leak kernel memory despite spectre v2 mitigations being in place to neutralize the branch predictor state was discovered...
  6. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue Advisory date: 2026-08-10 Packages: proxmox-kernel-* Details: A use-after-free issue in the Linux kernels SCTP code allowed a unprivileged local attacker to obtain root privileges, and potentially escape from unprivileged...
  7. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00036-1: "Zapscape" KVM guest to host escape on x86_64 Advisory date: 2026-08-10 Packages: proxmox-kernel-* Details: A use-after-free issue was discovered in the Linux kernel's KVM module's shadow MMU code. On hosts with nested virtualization enabled, this issue can be...
  8. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00035-1: missing privilege checks for container start-after-create/start-after-rollback Advisory date: 2026-08-03 Packages: pve-container Details: When creating a container or triggering a rollback to a snapshot, the VM.PowerMgmt privilege was not checked correctly if the...
  9. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00034-1: missing validation of comment field in firewall API Advisory date: 2026-08-03 Packages: pve-firewall, proxmox-firewall Details: Missing validation of the comment field in the firewall API allowed an authenticated attacker with privileges to modify at least one...
  10. ProxmoxSecurityAdvisory

    Proxmox Mail Gateway - Security Advisories

    Subject: PSA-2026-00033-1: Authenticated Remote Code Execution via custom_check_path setting Advisory date: 2026-08-03 Packages: pmg-api Details: The custom_check_path setting could be set by any user with 'Administrator' role. This script is executed for every mail received, with the path...
  11. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00032-1: "OVSWrap" local privilege escalation issue in OpenVSwitch Advisory date: 2026-07-29 Packages: proxmox-kernel-* Details: Two issues found in the Linux kernel's openvswitch module were discovered which allow leaking kernel addresses and decrementing arbitrary kernel...
  12. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00031-1: Several vulnerabilities found in the Linux kernel Advisory date: 2026-07-20 Packages: proxmox-kernel-6.17 Details: Various issues with security implications were discovered in the Linux kernel. Fixed in: - proxmox-kernel-6.17.13-18-pve(-signed) (Trixie based...
  13. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00030-1: Several vulnerabilities found in the Linux kernel Advisory date: 2026-07-20 Packages: proxmox-kernel-6.8 Details: Various issues with security implications were discovered in the Linux kernel. Fixed in: - proxmox-kernel-6.8.12-36-pve(-signed) (Bookworm based...
  14. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00029-1: overflow in ipv6 fragmentation code Advisory date: 2026-07-20 Packages: proxmox-kernel-* Details: An in-slab linear overflow issue was discovered in the Linux kernel's IPv6 fragementation code. This issue could be used to obtain root privileges as a local...
  15. ProxmoxSecurityAdvisory

    Proxmox Virtual Environment - Security Advisories

    Subject: PSA-2026-00028-1: "IonStack"/"GhostLock" use after free vulnerability in the Linux kernel Advisory date: 2026-07-20 Packages: proxmox-kernel-* Details: A Use-After-Free issue in the kernel's rtmutex/futex-PI code allows an attacker to write to arbitrary addresses. This can be used...