| State: |
published |
| Published at: |
2026-08-09 22:25:14 CEST |
| CVEs: |
CVE-2026-64189 |
| Name: |
ipset dump and resize race |
| Summary: |
English: Local privilege escalation |
| Česky: Lokální eskalace oprávnění |
| Description: |
English: A process with network-administration rights inside a VPS can race an ipset dump against set creation and access an array after it has been freed. The resulting shared-kernel memory corruption could give an attacker root inside the affected VPS. Because the corruption occurs in the shared node kernel, a more advanced exploit could potentially obtain root on the node. The reviewed technical evidence does not establish a complete path to node control and does not identify a mechanism for accessing another VPS. Failed attempts may crash the shared kernel. Kernel warnings that may indicate this bug was triggered are monitored. |
| Česky: Proces s oprávněním ke správě sítě uvnitř VPS může vyvolat souběh výpisu ipsetu s vytvořením sady a přistoupit k poli po jeho uvolnění. Následné poškození paměti sdíleného jádra by mohlo útočníkovi zajistit root uvnitř napadené VPS. Protože k poškození dochází ve sdíleném jádře node, pokročilejší zneužití by mohlo potenciálně získat root na node. Analyzované technické podklady nepopisují úplný postup k ovládnutí node ani mechanismus pro přístup do jiného VPS. Neúspěšný pokus může shodit sdílené jádro. Varování jádra, která mohou naznačovat spuštění této chyby, jsou monitorována. |
| Response: |
English: The fix for this CVE is included starting with vpsAdminOS kernel live patch 6.12.95.2. Upstream Linux includes it in 6.12.96 and later stable releases. |
| Česky: Oprava této zranitelnosti je součástí vpsAdminOS kernel live patche od verze 6.12.95.2. Ve stabilních vydáních Linuxu je obsažena od verze 6.12.96. |