Thanks to the Proxmox team for reviewing my report. At least they took it seriously, unlike the users on this forum who think that a Debian 11 installation is hacked simply because it's EOL (and no, the OpenSSH bug doesn't affect Debian 11; it's...
Found it. It is a complete compromise of the web interface. No pre-requisites, just a vulnerable proxmox version.
There was a bug patched in pve-access-control (potentially by accident) in 2023.
I will submit it to MITRE so a CVE can be issued...
The *immediate* fix, then.
Yes, absolutely, you should be on PVE 9 by now. I don't think anyone is contesting that.
I understand your frustration around change management. Most businesses should have either certifications or insurance that...
I think it's safe to say there is no official support for 3rd party products. The qualification matrix would be very complex, these are competing products, why would any vendor undertake this endeavor?
Blockbridge : Ultra low latency all-NVME...
Then you are still vulnerable due to the known and unknown security issues in PVE8 (which is EOL) and Debian Bookworm. The fix is to upgrade to the latest supported version of PVE aka PVE9 with every updated installed. Everything else is just...
Hello,
I'm not going to repeat what other users said / recommended - there are plenty of tutorials that more or less can get your AMD gpu working for VM passthrough.
My problem lays with very old and still preset in 9000 radeon gpu series issue...
So, you now got your security advisory for a vulnerability, in a over three year old version of a software component, which was at the time it would have been relevant neither internally discovered nor from anyone reported and hopefully also not...
eth0:0 kein echtes separates Interface ist, sondern nur ein Alias für eine zusätzliche IP auf eth0. Dein aktuelles Setup fügt die IP zwar korrekt hinzu, leitet aber keinen eingehenden Traffic automatisch zu einer VM oder einem anderen Ziel...
That service is currently used to transfer a VM’s connection-tracking state during live migration, so established connections (within the guest) continue to be recognized by stateful firewalls on the target node.
The stale object should not be...
eth0:0 kein echtes separates Interface ist, sondern nur ein Alias für eine zusätzliche IP auf eth0. Dein aktuelles Setup fügt die IP zwar korrekt hinzu, leitet aber keinen eingehenden Traffic automatisch zu einer VM oder einem anderen Ziel...
That service is currently used to transfer a VM’s connection-tracking state during live migration, so established connections (within the guest) continue to be recognized by stateful firewalls on the target node.
The stale object should not be...
Thanks for clarification.
So basically you should not be affected if your CPU desgin is 2019 or newer as CVE is dated 2018.
My rather new AMD Epyc are not affected.
root@xxxxxx ~ # cat /sys/devices/system/cpu/vulnerabilities/itlb_multihit
Not...