runc CVE-2024-21626: LXC container escape patch
A runtime container vulnerability can allow access to the host filesystem; the patched version in the PVE repositories should be installed.
A runtime container vulnerability can allow access to the host filesystem; the patched version in the PVE repositories should be installed.
CVE-2024-21626, runc's WORKDIR handling bug allows escaping from a container to the host filesystem. The direct impact on PVE is limited because the LXC infrastructure in PVE does not use runc; however, the risk is high for VMs and CTs running nested Docker/Podman.
apt dist-upgrade to install up-to-date kernel and userland packagesunprivileged modeA cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.