| Version(s) | Toggle summary | ||||
|---|---|---|---|---|---|
| RHSB-2026-011 Network Stack Privilege Escalations | Low | CVE-2026-80844,CVE-2026-81000 & CVE-2026-74469,CVE-2026-68121 | <4.5.1 | ||
A recent Red Hat Security Bulletin (RHSB) has been posted which covers the following high profile CVEs: CVE-2026-80844 (DirtyAH6) CVE-2026-81000 (TUNderflow) CVE-2026-68121 (PPPoEject) CVE-2026-74469 (DiagSpill) It is important to note that these vulnerabilities all require local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. Or for a user with admin level access, who would already have sufficient permissions and access that they would not need to exploit any known vulnerabilities to carry out destructive actions. As such these are vulnerabilities are not considered ‘exploitable’ under practical operational conditions. The following CVEs: CVE-2026-80844 (DirtyAH6) CVE-2026-81000 (TUNderflow) CVE-2026-68121 (PPPoEject) Are mitigated by default in all 4.x VQCM instances due to the preset user.max_user_namespaces value (0). All 4.5.1 or later VQCMs are also protected against CVE-2026-74469 (DiagSpill) as the impacted module (sctp) is blacklisted by default. A playbook to mitigate CVE-2026-74469 (DiagSpill) has been put together to ensure the impacted module (sctp) is not loaded and that the default mitigation for CVE-2026-80844 (DirtyAH6), CVE-2026-81000 (TUNderflow) and CVE-2026-68121 (PPPoEject) is inplace. Customers who are on VQCMs older than 4.5.1 or who believe the defaults within their VQCM VM may have been altered, please raise a support ticket (via support@vqcomms.com) to request access to the mitigation playbook. If customers are unsure if they need to raise a support ticket, they can run the following commands (via the CLI to check). These commands will require elevated privileges to run: grep -E ‘^(blacklist sctp|install sctp /bin/false)’ /etc/modprobe.d/blacklist.conf The above should return two lines: blacklist sctp install sctp /bin/false If their is no return value, this is a finding and you need to raise a ticket with VQ Support To ensure that the default mitigation is in place, please run: sysctl user.max_user_namespaces This should show user.max_user_namespaces = 0 If the value is anything different, this is a finding and you need to raise a ticket with VQ Support If customers have any questions or concerns, please email security@vqcomms.com | |||||
| PostGREShell | High | CVE-2026-6471 | HA (All) | ||
We are aware of Postgres replication vulnerability known as ‘PostGREShell’ Within a standard VQ Conference Manager (VQCM) instance the PostgreSQL instance is not externally exposed, therefore requiring CLI access to the VQCM itself to attempt to exploit. At the point of access an attacker can already carry code execution on the host system. On a VQCM High Availability (HA) deployment an attacker would need to have credentials for a valid replication user, this would initially require access to a VQCM HA instance, which again would allow the attacker to carry out code execution without exploitation of this vulnerability in the first instance. This vulnerability impacts all VQCM HA releases, we are currently working on a VQCM HA release which will have a fixed version of the PostgreSQL instance and will update customers once this is available. Customers with existing VQCM HA instances that they can not upgrade or who wish to discuss this CVE and their own risk profile should email security@vqcomms.com | |||||
| SCTPhantom | Informational | CVE-2026-64564 | 4.x | ||
We are aware of the high profile ‘SCTPhantom’ exploit which impacts the Linux kernel. It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM and by default are blacklisted in the kernel. As such there should be no need for action to mitigate unless customers have specifically enabled this module. If customers are unsure or if you have any questions about this CVE, please email security@vqcomms.com | |||||
| OVSwrap | Low | CVE-2026-64531 | 4.9.0 | ||
We are aware of the high profile ‘OVSwrap’ exploit which impacts the RHEL 9 kernel. It is important to note that this exploit only impacts VQCM 4.9.0 and that it requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM, preventing exploitation without a privileged user first having loaded these modules. To ensure peace of mind for our customers and meet the our high levels of security and transparency we have made available a mitigation playbook which can be applied to a running VQCM instance. This will make sure the impacted modules are not loaded and prevent them from being loaded in the future. This should not impact the running VQCM instance at all and there should be no down time. If you have any questions about this CVE, please email security@vqcomms.com To request access to the playbook, please email support@vqcomms.com | |||||
| RefluXFS | Medium | CVE-2026-64600 | 4.x | ||
We are aware of the recent Local Privilege Escalations (LPEs) exploit RefluXFS. It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The recently released VQCM 4.9.0 (and all older versions) are impacted by this vulnerability, as such we have put together a playbook to apply the updated kernel version. This should be run on a VQCM 4.9.0 as this version also contains multiple other security fixes. Customers who are on 4.9.0 and wish to apply this patch should contact VQ Support. Please be aware that for the fix to take effect the VQCM instance will need to be rebooted, so this patch can not be run during operational hours. | |||||
| GhostLock | Low | CVE-2026-43499 | 4.x | ||
We are aware of the recent Local Privilege Escalations (LPEs) exploit GhostLock. It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. At the time of writing Red Hat have not released an upstream patch or fix, so current advice to customers to ensure the security of their system is to prevent untrusted actors or unauthorised users from accessing the VQ Conference Manager in the first instance. Customers with externally exposed SSH or admin portals instances will be most at risk. Customers who are concerned about this issue are advised to get in contact via support@vqcomms.com | |||||
| Bad Epoll | Informational | CVE-2026-46242 | 4.x | ||
We are aware of the recent Local Privilege Escalations (LPEs) exploit Bad Epoll. This vulnerability, while wide spread does not impact the Red Hat Enterprise Linux 8 Operating System (OS). This is the OS used by all 4.x VQ Conference Manager releases to date. The next VQ Conference Manager release will be on a later OS, but will released with a patched kernel version. No action is or will be needed by customers. | |||||
| Dirty Clone and pedit COW | Informational | CVE-2026-43503 and CVE-2026-46331 | 4.x | ||
We are aware of the recent Local Privilege Escalations (LPEs) exploits impacting the Linux kernel (Dirty Clone and pedit COW). It is important to note that these exploits requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. Both vulnerabilities (and associated exploits) are mitigated by having the user.max_user_namespaces set to 0. This is the default value for the 4.x VQCM, as such no action should need to be taken by customers. If customers believe there is a chance their kernel value has been changed or they wish to discuss these vulnerabilities (or any other security issues) please get in contact via support@vqcomms.com | |||||
| Copy Fail | Low | CVE-2026-31431 | 4.x | ||
We are aware of the high profile ‘Copy Fail’ vulnerability which impacts all Linux kernel versions since 2017 (CVE-2026-31431). It is important to note that this vulnerability requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The vast majority of our micro-services all run with allowPrivilegeEscalation set to false which further lows the potential risk. However given the volatile nature of cyber security, and to ensure we continue to meet high levels of security and transparency we have made available a mitigation playbook which can be applied to a running VQCM instance. This will require a restart of VQCM VM for the mitigation to take effect, and will disable the vulnerable Linux kernel module If you have any questions about this CVE, please email security@vqcomms.com To request access to the playbook, please email support@vqcomms.com | |||||
| Dirty Frag | Low | CVE-2026-43284 and CVE-2026-43500 | 4.x | ||
We are aware of the high profile ‘Dirty Frag’ exploit which impacts all current Linux kernel versions. It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM, preventing exploitation without a privileged user first having loaded these modules. To ensure peace of mind for our customers and meet the our high levels of security and transparency we have made available a mitigation playbook which can be applied to a running VQCM instance. This will make sure the impacted modules are not loaded and prevent them from being loaded in the future. This should not impact the running VQCM instance at all and there should be no down time. If you have any questions about this CVE, please email security@vqcomms.com To request access to the playbook, please email support@vqcomms.com | |||||
| PinTheft | Low | CVE-2026-46333 | 4.x | ||
We are aware of the recent CVE-2026-46333 which has a public exploit (‘PinTheft’) and impacts major Linux kernel versions, RHEL included. It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM, preventing exploitation without a privileged user first having loaded these modules. To ensure peace of mind for our customers and meet the our high levels of security and transparency we have made available a mitigation playbook which can be applied to a running VQCM instance. This will make sure the required changes are made the to the kernel ptrace scope. If you have any questions about this CVE, please email security@vqcomms.com To request access to the playbook, please email support@vqcomms.com | |||||
| AspNetCore.DataProtection – Privilege Escalation | Informational | CVE-2026-40372 | 4.8.0 | ||
We are aware of the recent security advisories around CVE-2026-40372 which impacts the Microsoft.AspNetCore.DataProtection.* NuGet packages (10.0.0-10.0.6). This is a vulnerability which allows for padding attacks against impacted systems, this is a non-trivial attack vector which requires network access to impacted systems for an extended period of time. We have carried out a review of our systems and found that this does not impact the VQCM instance as we do not load or use a NuGet Microsoft.AspNetCore.DataProtection.* at runtime. However out of an abundance of caution and to ensure we continue to meet high levels of security and transparency we have made available a patch playbook. This will replace the Identity Server image on the VQCM, which handles authentication and token generation for user sessions. Once the playbook has been run users will need to shut down any open browsers sessions to the VQCM instance and log back in. If you experience issues logging in we suggest clearing your browser history and using a new private browsing session to avoid issues with session caching. | |||||
No advisories match the current filter.