The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed...
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
I'm unrelated to the other user, the only reason I signed up was after seeing the post on the other forum :)
If I remember correctly at the time Debian 11 wasn't affected by that SSH bug
EDIT: I found this and it seems like Debian 11 wasn't...
Not sure what you mean by "Everything". So far you only reported your own single host being attacked.
Are you (by chance) connected to arjitc, the other reporter of this attack. (Interestingly both these users only joined today, for the purpose...
Only to you, unless you are claiming that it affects an up-to-date version of PVE.
PVE 7 is based on Debian 11, PVE 8 on Debian 12. So they would be affected by that bug unless they were updated since the bug was fixed.
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...
Search for 8. in these posts here: https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/ . PVE 8 is also vulnerable to lots of things unless completely up to date but it most likely does not get any updates...
I can confirm EnablePerCpuClockTickScheduling=2 fixes / works around the issue. CPU load returns to 23H2 levels and CPU cores assigned to the VM are able to enter deeper C states as expected. Thank you!
I've attached this info to the QEMU ticket...
Not sure what you mean by "Everything". So far you only reported your own single host being attacked.
Are you (by chance) connected to arjitc, the other reporter of this attack. (Interestingly both these users only joined today, for the purpose...
Only to you, unless you are claiming that it affects an up-to-date version of PVE.
PVE 7 is based on Debian 11, PVE 8 on Debian 12. So they would be affected by that bug unless they were updated since the bug was fixed.
Ehrlich gesagt ändert das bei Debian doch wenig, mit dem DCO lag die Verantwortung schon immer beim Einreicher. Ungeprüft zusammenkopierten Kram gab's auch vorher schon, halt von Stack Overflow statt vom LLM. Was real schützt ist der Review- und...
Everything happened on the same day at the same time. Of course, it's a zero-day vulnerability and affects several versions of Proxmox. Exposing Proxmox to the internet doesn't make it hackable with a single click. There are no publicly available...
So, you are:
Running a OS that is EOL since two years
Exposing it to the internet
Disabling the firewall
If this is not a troll, I hope the lesson was learned...
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...