Security bulletins

NetUser

Member
Sep 20, 2021
27
1
6
28
Hi,

I've looked for proxmox security bulletins or so on, but i couldn't find anything but single CVEs when they happens.
Is there a dedicated newsletter when i can find fixed vulnerabilities in this version etc?

Thanks in advance!
 
  • Like
Reactions: Polkaroo
Would be interested in that too.
I guess following Debian + Ubuntu bulletins should work too, as PVE is based on Debian and using a modified ubuntu kernel.
 
There is currently no centralized place where such announcements are collected. We monitor relevant upstreams like the Linux kernel project, Qemu, LXC as well as dependencies we use in our software and pull in fixes in a timely fashion. Any packages provided directly by the stock Debian repositories is covered by DSAs (https://security.debian.org).

For the kernel in particular, each upstream stable release usually fixes multiple security relevant issues/bugs, both with CVEs assigned and without any special identifiers attached. We don't reproduce the full changelog of our base kernel (which is maintained by Ubuntu), but include its version number so that you can look it up. Whenever we cherry-pick a CVE fix ahead of or in parallel of Ubuntu, we do call it out in our kernel changelog. The same applies to Qemu as well.
 
I guess a centralized list summing up all CVEs would be quite terrifying to see for all those people sticking with PVE 5.X and 6.X ;)
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!