I couldn't reproduce this. On my side, with 4 containers (no Start/Shutdown order set) and max-workers at the default of 4, all four kick off at once and finish in a couple of seconds - no serial behavior. I also printed the worker count in the...
According to the docs: "If the NUMA option is used, it is recommended to set the number of sockets tothe number of nodes of the host system." Have you tried that and checked how it changes your situation/problem...
Thanks to the Proxmox team for reviewing my report. At least they took it seriously, unlike the users on this forum who think that a Debian 11 installation is hacked simply because it's EOL (and no, the OpenSSH bug doesn't affect Debian 11; it's...
Hi all,
We have a question regarding best practices and recommended settings for NUMA and the number of CPU sockets assigned to a VM.
We need to support memory hot-plug, which means we are currently running these VMs with NUMA=1. Our...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed...
To be honest, I'm sick of this whole discussion. The newly registered users who were actually affected have already admitted that running an outdated system was a mistake. Meanwhile, some of the so-called veteran users on this forum just keep...
hi, nice work.
Did you consider sending patches directly instead of making a standalone thing?
While we're probably wouldn't integrate react+vite, we're using our own rust based ui framework (that we use e.g. for the user quarantine mobile...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
Der Lizenz-Punkt von @Johannes S ist eigentlich der spannendere, das Codestyle-Argument erledigt sich ja mit genug Nachdruck im Review. Beim DCO unterschreibst du nicht nur "ich steh dafür grade", sondern auch dass du das Recht hast, den Code...
Du hast "Das Geschäftsmodell der AI-Codeassistenten beruht auf systematischen Verstoßen gegen Urheberrecht und opensource-Lizenzen" sehr umständlich ausgedrückt :)
Weil auch wenn das Problem nicht grundsätzlich neu ist, erreicht es so doch eine...
Ich sehe ( und das als bekennender KI-Luddit!) auch nicht so das Problem. Im Grunde sagt Debian, dass „aber die ki sagt, das passt so“ keine erlaubte Ausrede ist Bullshit abzuliefern ;)
OpenBSD hatte ja das Vergnügen mit einen Vibecoder, der...
Ehrlich gesagt ändert das bei Debian doch wenig, mit dem DCO lag die Verantwortung schon immer beim Einreicher. Ungeprüft zusammenkopierten Kram gab's auch vorher schon, halt von Stack Overflow statt vom LLM. Was real schützt ist der Review- und...
You're absolutely right, and I accept the failure on my side.
Just to clarify, this is informational, not a complaint. I'm sharing it so you're aware that this actually happened in our environment and can take it into account.
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
Thanks to the Proxmox team for reviewing my report. At least they took it seriously, unlike the users on this forum who think that a Debian 11 installation is hacked simply because it's EOL (and no, the OpenSSH bug doesn't affect Debian 11; it's...
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...
Hello everyone
Do any of you know this problem and how to solve it? The PMG "daily admin report" is always sent twice when triggered automatically. If I run the job manually (pmgreport --receiver admin@dummy.com --timespan today --auto), only...