Proxmox and CVE-2014-0196

We will include that as soon as we get a patch for 2.6.32. But there are normally no local users on PVE nodes.
 
Thanks for the update!Concerning the local users: Any idea if this could be exploited from inside a OpenVZ container?best regards,Michael
 
Hello,
openvz CT's are using the same kernel from openvz node. Only what you need is check the kernel on the node. According to OpenVZ news:
OpenVZ Containers @_openvz_ · May 13 CVE-2014-0196: if you haven't updated your openvz kernel / rebooted during last 12 months, please do that now.



CVE-2014-0196 update: OpenVZ kernels since 042stab076.7 (released a year ago, April 2013) are not exploitable. Older ones are.





 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!