Security advisory #11

Information

State: published
Published at: 2026-08-09 22:24:48 CEST
CVEs: CVE-2025-37964
Name: x86 TLB switch ordering race
Summary: English: Local privilege escalation
Česky: Lokální eskalace oprávnění
Description: English: Concurrent address-space switching and memory invalidation can leave stale translations active in the shared x86 kernel. A process can then access a physical page after it has been reassigned, which may expose or corrupt kernel or VPS memory. Exploitation could give an attacker root inside the affected VPS. Because the stale translation affects the shared node kernel, an attacker who controls physical-page reuse could potentially obtain root on the node or access data from another VPS. The reviewed technical evidence does not establish a complete exploit path to either outcome. The race may also cause process faults or a kernel crash. Kernel warnings that may indicate this bug was triggered are monitored.
Česky: Souběh při přepínání adresního prostoru a zneplatňování paměti může ve sdíleném jádře x86 ponechat aktivní zastaralé překlady. Proces pak může přistoupit k fyzické stránce poté, co byla přidělena jinam, a odhalit nebo poškodit paměť jádra či VPS. Zneužití by mohlo útočníkovi zajistit root uvnitř napadené VPS. Protože zastaralý překlad zasahuje sdílené jádro node, útočník schopný řídit opětovné využití fyzické stránky by mohl potenciálně získat root na node nebo přístup k datům jiného VPS. Analyzované technické podklady nepopisují úplný postup vedoucí k žádnému z těchto dopadů. Souběh může také způsobit chyby procesů nebo pád jádra. Varování jádra, která mohou naznačovat spuštění této chyby, jsou monitorována.
Response: English: The effective correction is included starting with vpsAdminOS kernel live patch 6.12.95.2. Earlier Linux 6.1, 6.6, and 6.12 stable backports did not close the race because their operations were ordered incorrectly; the accepted live patch contains the stable-specific correction.
Česky: Účinná oprava je součástí vpsAdminOS kernel live patche od verze 6.12.95.2. Starší backporty pro stabilní řady Linuxu 6.1, 6.6 a 6.12 souběh neuzavřely kvůli nesprávnému pořadí operací; přijatý live patch obsahuje opravu určenou pro tyto stabilní řady.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-06 04:45:59 CEST 2026-08-06 04:46:29 CEST
node20.prg mitigated 2026-08-06 04:46:05 CEST 2026-08-06 04:46:36 CEST
node21.prg mitigated 2026-08-06 04:46:08 CEST 2026-08-06 04:46:38 CEST
node22.prg mitigated 2026-08-06 04:45:54 CEST 2026-08-06 04:46:24 CEST
node23.prg mitigated 2026-08-06 04:46:04 CEST 2026-08-06 04:46:34 CEST
node24.prg mitigated 2026-08-06 04:46:25 CEST 2026-08-06 04:46:55 CEST
node25.prg mitigated 2026-08-06 04:46:16 CEST 2026-08-06 04:46:46 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-09 05:05:47 CEST 2026-08-09 05:06:17 CEST
node6.brq mitigated 2026-08-06 04:46:23 CEST 2026-08-06 04:46:53 CEST
node1.pgnd mitigated 2026-08-06 04:24:40 CEST 2026-08-06 04:25:10 CEST
node1.stg mitigated 2026-08-06 03:30:50 CEST 2026-08-06 03:31:39 CEST
node2.stg mitigated 2026-08-06 03:29:49 CEST 2026-08-06 03:30:14 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791