<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Proxmox | OKHK 👀</title><description>(⁠◔⁠‿⁠◔⁠) Are you OK？✨ Thinking...</description><link>https://tg.okhk.net</link><item><title>🔴 Proxmox VE 远程提权漏洞；建议升级至 PVE 9</title><link>https://tg.okhk.net/posts/11155</link><guid isPermaLink="true">https://tg.okhk.net/posts/11155</guid><pubDate>Wed, 02 Sep 2026 09:34:42 GMT</pubDate><content:encoded>&lt;div class=&quot;tgme_widget_message_forwarded_from accent_color&quot;&gt;Forwarded from &lt;a class=&quot;tgme_widget_message_forwarded_from_name&quot; href=&quot;https://t.me/outvivid/4910&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;span&gt;层叠 - The Cascading&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;i class=&quot;emoji&quot;&gt;&lt;b&gt;🔴&lt;/b&gt;&lt;/i&gt; &lt;mark class=&quot;highlight&quot;&gt;Proxmox&lt;/mark&gt; VE 远程提权漏洞；建议升级至 PVE 9。&lt;br /&gt;&lt;br /&gt;- 骇客可以通过 API 访问未启用 2FA 的账户（包括 root）。&lt;br /&gt;- 官方建议更新至依然支持的版本，也就是 PVE 9；PVE 8 已于 8/31 结束支持。&lt;br /&gt;- ……或者执行 mitigation 代码。&lt;br /&gt;- 影响 libpve-access-control 的 7.0-7（含）至 8.0.4（不含）版本，但这个版本号和 PVE 版本号并非对应关系。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;forum.proxmox.com/~&quot;&gt;forum.proxmox.com/~&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23Proxmox&quot; title=&quot;#Proxmox&quot;&gt;#Proxmox&lt;/a&gt;&lt;a class=&quot;tgme_widget_message_link_preview&quot; href=&quot;https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issueAdvisory date: 2026-08-10Packages: proxmox-kernel-*Details:A use-after-free issue in the Linux kernels SCTP code...&quot;&gt;
  &lt;i class=&quot;link_preview_right_image&quot; style=&quot;background-image:url(&apos;https://cdn4.telesco.pe/file/YfHdB64o5MGHlVkFiQ75ki6_RQsGBJdNN4mKNh1QaksxfvxI8LACky87YnNz2kp4M-Uetqt48iSrNoxWeGoa0wo0c-pvt8ONhHjBHZJI3CM8Gm6J1DxntPyQj8GoYtzdqY_nSqyZGYo_VSmpsDo_2L1f_IsnAielJsBWkp4MBcYr36RaBpg5Ra3t2Yx8i_stlVZVTyD9xjUud9YSGIP4o4wtXiEHmCu5bRWxS6sFl14y3fWVc1zxJtTH_1J5xhqVhKDV2QsEjHGbKLNux1IgBXXeUpFflbLHCjBC8FGbyBG-G0hVidv3CVTZ2igMF5tKxA7eH3FkgiVrReSrVIs2kw.jpg&apos;)&quot;&gt;&lt;/i&gt;
  &lt;div class=&quot;link_preview_site_name accent_color&quot;&gt;Proxmox Support Forum&lt;/div&gt;
  
  &lt;div class=&quot;link_preview_title&quot;&gt;&lt;mark class=&quot;highlight&quot;&gt;Proxmox&lt;/mark&gt; Virtual Environment - Security Advisories&lt;/div&gt;
  &lt;div class=&quot;link_preview_description&quot;&gt;Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue&lt;br /&gt;&lt;br /&gt;Advisory date: 2026-08-10&lt;br /&gt;&lt;br /&gt;Packages: &lt;mark class=&quot;highlight&quot;&gt;proxmox&lt;/mark&gt;-kernel-*&lt;br /&gt;&lt;br /&gt;Details:&lt;br /&gt;&lt;br /&gt;A use-after-free issue in the Linux kernels SCTP code...&lt;/div&gt;
&lt;/a&gt;</content:encoded></item></channel></rss>