Security advisory #24

Information

State: published
Published at: 2026-08-09 22:27:22 CEST
CVEs: CVE-2026-64580
Name: XFRM6 device reference underflow
Summary: English: Denial of service
Česky: Odepření služby
Description: English: A process with network-administration rights inside a VPS can exercise an IPv6 XFRM error path that releases the same network-device reference twice. The underflow can keep device teardown waiting indefinitely or lead to use of a stale device. The flaw does not directly provide root inside a VPS. The reviewed technical evidence establishes an availability risk, but does not identify a path to root on the node or access to another VPS. Repeated triggers may hang networking or crash the shared kernel and affect node availability. Kernel warnings that may indicate this bug was triggered are monitored.
Česky: Proces s oprávněním ke správě sítě uvnitř VPS může vyvolat chybovou cestu IPv6 XFRM, která dvakrát uvolní stejnou referenci síťového zařízení. Podtečení může způsobit nekonečné čekání při odstraňování zařízení nebo použití neplatného zařízení. Chyba přímo neposkytuje root uvnitř VPS. Analyzované technické podklady dokládají riziko pro dostupnost, ale neuvádějí postup k získání root na node ani k přístupu do jiného VPS. Opakované vyvolání může zablokovat síť nebo shodit sdílené jádro a ovlivnit dostupnost node. Varování jádra, která mohou naznačovat spuštění této chyby, jsou monitorována.
Response: English: The fix for this CVE is included starting with vpsAdminOS kernel live patch 6.12.95.2. Upstream Linux includes it in 6.12.101 and later stable releases.
Česky: Oprava této zranitelnosti je součástí vpsAdminOS kernel live patche od verze 6.12.95.2. Ve stabilních vydáních Linuxu je obsažena od verze 6.12.101.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-06 04:45:59 CEST 2026-08-06 04:46:29 CEST
node20.prg mitigated 2026-08-06 04:46:05 CEST 2026-08-06 04:46:36 CEST
node21.prg mitigated 2026-08-06 04:46:08 CEST 2026-08-06 04:46:38 CEST
node22.prg mitigated 2026-08-06 04:45:54 CEST 2026-08-06 04:46:24 CEST
node23.prg mitigated 2026-08-06 04:46:04 CEST 2026-08-06 04:46:34 CEST
node24.prg mitigated 2026-08-06 04:46:25 CEST 2026-08-06 04:46:55 CEST
node25.prg mitigated 2026-08-06 04:46:16 CEST 2026-08-06 04:46:46 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-09 05:05:47 CEST 2026-08-09 05:06:17 CEST
node6.brq mitigated 2026-08-06 04:46:23 CEST 2026-08-06 04:46:53 CEST
node1.pgnd mitigated 2026-08-06 04:24:40 CEST 2026-08-06 04:25:10 CEST
node1.stg mitigated 2026-08-06 03:30:50 CEST 2026-08-06 03:31:39 CEST
node2.stg mitigated 2026-08-06 03:29:49 CEST 2026-08-06 03:30:14 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791