New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
PSA: Prepare for another emergency reboot (CVE-2026-64560)
Thankfully this is not a KVM escape so nodes won't have to reboot as fast, but the guests sure should.
The bug, CVE-2026-64560, is a UAF in the POSIX timer subsystem, and allows rather simple privilege escalation.
See detailed description in commit 920f893f735e92ba3a1cd9256899a186b161928d.
Unfortunately, there's not even a fix in Debian yet (besides Sid), but see their security tracker for updates.


Comments
great success--every day
AI really fucked things up
fuck
This kind of LPE happens regularly in Linux and it's why you can't use Docker as a security boundary. You would have to have already escaped a VM to use this against a VM host.
Is a full reboot actually necessary even if I use LivePatch to keep the kernel up to date with security patches?
The RHEL errata classifies this (for now) as moderate severity and states that it does not affect RHEL 7.x and 8.x.
But there's also this shit (OVSwrap, CVE-2026-64531):
https://blog.cloudlinux.com/ovswrap-cve-2026-64531-mitigation/
It is becoming a new reality, so all we can do it to accept it and continue to live [preferably happily].