Proxmox Virtual Environment - Security Advisories

Status
Not open for further replies.

Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue​


Advisory date: 2026-08-10

Packages: proxmox-kernel-*

Details:

A use-after-free issue in the Linux kernels SCTP code allowed a unprivileged local attacker to obtain root privileges, and potentially escape from unprivileged containers.

Mitigations:

Preventing the sctp module from being loaded mitigates the issue.

Fixed in:
- proxmox-kernel-7.0.14-10-pve(-signed) (Trixie based products)
- proxmox-kernel-6.8.12-41-pve(-signed) (Bookworm based products)

References:
- CVE-2026-64564
- https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
 

Subject: PSA-2026-00038-1: TONTOU kernel memory leak via branch predictor re-poisoning​


Advisory date: 2026-08-10

Packages: proxmox-kernel-*

Details:

A new technique to leak kernel memory despite spectre v2 mitigations being in place to neutralize the branch predictor state was discovered. This technique uses interrupt injection to re-poison the branch predictor during the window between neutralization and return of execution.

This technique is only applicable on AMD and Intel CPUs.

Fixed in:
- proxmox-kernel-7.0.14-11-pve(-signed) (Trixie based products)
- proxmox-kernel-6.8.12-41-pve(-signed) (Bookworm based products)

References:
- CVE-2026-68480
- https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf (paper, PDF)
 
Status
Not open for further replies.