Incomplete validation of an S3 object key returned by a configured S3 endpoint allowed an attacker with control over the S3 server to overwrite arbitrary host paths as user/group backup when an S3-refresh is triggered.
This issue was reported privately by Project Loupe.
An attacker with direct access to a PBS datastore configured as storage on a Proxmox VE host can construct and upload a malicious pxar archive with two root entries.
When such a backup archive was restored by pve-container, the archive contents were written outside of the target rootfs mountpoint. If a container is restored as privileged container, the extraction runs as root.
proxmox-backup-client will now refuse to follow symlinks during extraction of directories or hardlinks.
This issue was reported privately by Project Loupe.
Subject: PSA-2026-00061-1: Missing validation of chunk sizes during pull sync
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
An attacker with control over a pull source (or its raw index contents) could trick the pull target into storing an index file with an invalid reference to a valid chunk. Subsequent verification of that index will treat the chunk as corrupt, breaking availability of other valid snapshots referencing it.
This issue was reported privately by Project Loupe.