Security advisory #31

Information

State: published
Published at: 2026-08-23 09:43:56 CEST
CVEs: CVE-2026-64017
Name: blk-mq cached request use-after-free
Summary: English: Local privilege escalation
Česky: Lokální eskalace oprávnění
Description: English: A process inside a VPS can submit block I/O while the shared kernel is reusing cached requests. If the task blocks between inspecting and removing a cached request, a plug flush can free that request before it is used. The resulting use-after-free could give an attacker root inside the affected VPS. Because the corruption occurs in the shared kernel, a more advanced exploit could potentially obtain root on the node. The reviewed technical evidence does not establish a complete node-control path or a mechanism for accessing another VPS. Failed attempts may crash the shared kernel and affect node availability. Kernel warnings that may indicate this bug was triggered are monitored.
Česky: Proces uvnitř VPS může odesílat blokové I/O ve chvíli, kdy sdílené jádro znovu používá uložené požadavky. Pokud se proces uspí mezi kontrolou a odebráním uloženého požadavku, vyprázdnění fronty jej může uvolnit před použitím. Následný přístup do uvolněné paměti by mohl útočníkovi zajistit root uvnitř napadené VPS. Protože k poškození dochází ve sdíleném jádře, pokročilejší zneužití by mohlo potenciálně získat root na node. Analyzované technické podklady nepopisují úplný postup k ovládnutí node ani mechanismus pro přístup do jiného VPS. Neúspěšné pokusy mohou shodit sdílené jádro a ovlivnit dostupnost node. Varování jádra, která mohou naznačovat spuštění této chyby, jsou monitorována.
Response: English: The fix for this CVE is included starting with vpsAdminOS kernel live patch 6.12.95.6. It removes a usable cached request before any operation that can block, keeping the request valid while I/O is dispatched. Upstream Linux includes the fix in 6.12.104 and later stable releases.
Česky: Oprava této zranitelnosti je součástí vpsAdminOS kernel live patche od verze 6.12.95.6. Použitelný uložený požadavek odebere před operací, která může proces uspat, a udrží jej platný při předání I/O ovladači. Ve stabilních vydáních Linuxu je oprava obsažena od verze 6.12.104.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-22 18:07:18 CEST 2026-08-22 18:07:48 CEST
node20.prg mitigated 2026-08-22 18:06:58 CEST 2026-08-22 18:07:28 CEST
node21.prg mitigated 2026-08-22 18:07:33 CEST 2026-08-22 18:08:31 CEST
node22.prg mitigated 2026-08-22 18:08:09 CEST 2026-08-22 18:08:39 CEST
node23.prg mitigated 2026-08-22 18:23:35 CEST 2026-08-22 18:24:45 CEST
node24.prg mitigated 2026-08-22 18:08:31 CEST 2026-08-22 18:24:26 CEST
node25.prg mitigated 2026-08-22 18:05:42 CEST 2026-08-22 18:06:15 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-22 17:58:09 CEST 2026-08-22 17:58:39 CEST
node6.brq mitigated 2026-08-22 17:51:28 CEST 2026-08-22 17:51:58 CEST
node1.pgnd mitigated 2026-08-22 18:08:29 CEST 2026-08-22 18:19:00 CEST
node1.stg mitigated 2026-08-22 17:32:27 CEST 2026-08-22 17:33:29 CEST
node2.stg mitigated 2026-08-22 17:43:44 CEST 2026-08-22 17:44:14 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791