Security advisory #6

Information

State: published
Published at: 2026-07-21 22:00:00 CEST
CVEs: CVE-2026-23111
Name: nf_tables catchall verdict UAF
Summary: English: Local privilege escalation
Česky: Lokální eskalace oprávnění
Description: English: The vulnerable nf_tables operation is available to ordinary VPS processes and can corrupt shared kernel state. Reliable exploitation could give the attacker root inside the affected VPS, meaning full control of that VPS. No escape to root on the node or access to another VPS has been demonstrated. Failed attempts can fault the shared kernel and affect node availability. Kernel warnings that may indicate this bug was triggered are monitored.
Česky: Zranitelná operace v nf_tables je dostupná běžným procesům ve VPS a může poškodit stav sdíleného jádra. Spolehlivé zneužití by útočníkovi mohlo dát root uvnitř napadeného VPS, tedy plnou kontrolu nad tímto VPS. Únik na root na node ani přístup do jiného VPS nebyl prokázán. Neúspěšné pokusy mohou vyvolat chybu sdíleného jádra a ovlivnit dostupnost node. Varování jádra, která mohou naznačovat spuštění této chyby, jsou monitorována.
Response: English: The fix is included in Linux 6.12.70 and later. vpsAdminOS overwrites newly allocated and released kernel memory, randomizes internal allocation behavior, and keeps some object types apart. This makes reliable reuse of released memory harder, but it does not remove the bug. The status below shows the result and any affected interval for each node.
Česky: Oprava je součástí Linuxu 6.12.70 a novějších. vpsAdminOS přepisuje nově přidělenou i uvolněnou paměť jádra, náhodně mění způsob jejího přidělování a odděluje některé typy objektů. Spolehlivé využití uvolněné paměti je proto obtížnější, chyba tím ale není odstraněna. Stav níže uvádí výsledek a případný interval ohrožení pro každý node.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-07-07 01:24:51 CEST 2026-07-07 01:24:51 CEST
node20.prg mitigated 2026-03-13 11:50:39 CET 2026-03-13 11:50:39 CET
node21.prg mitigated 2026-04-30 16:51:58 CEST 2026-04-30 16:51:58 CEST
node22.prg mitigated 2026-07-07 02:21:28 CEST 2026-07-07 02:21:28 CEST
node23.prg mitigated 2026-03-07 18:52:27 CET 2026-03-07 18:52:27 CET
node24.prg mitigated 2026-02-22 02:05:39 CET 2026-02-22 02:05:39 CET
node25.prg not affected - -
backuper2.prg not affected - -
node5.brq mitigated 2026-03-30 09:47:14 CEST 2026-03-30 09:47:14 CEST
node6.brq mitigated 2026-02-21 22:32:19 CET 2026-02-21 22:32:19 CET
node1.pgnd mitigated 2026-06-10 18:43:56 CEST 2026-06-10 18:43:56 CEST
node1.stg mitigated 2026-03-01 11:13:57 CET 2026-03-01 11:13:57 CET
node2.stg not affected - -

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791