New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
PSA: Prepare for another emergency reboot (CVE-2026-64560)
Thankfully this is not a KVM escape so nodes won't have to reboot as fast, but the guests sure should.
The bug, CVE-2026-64560, is a UAF in the POSIX timer subsystem, and allows rather simple privilege escalation.
See detailed description in commit 920f893f735e92ba3a1cd9256899a186b161928d.
Unfortunately, there's not even a fix in Debian yet (besides Sid), but see their security tracker for updates.

Comments
great success--every day
AI really fucked things up
fuck
This kind of LPE happens regularly in Linux and it's why you can't use Docker as a security boundary. You would have to have already escaped a VM to use this against a VM host.
Is a full reboot actually necessary even if I use LivePatch to keep the kernel up to date with security patches?