<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security | PFCP</title>
    <link>https://pfcomputing.com/en/categories/security/</link>
    <description>Security</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 23 Jul 2026 13:00:00 +0900</lastBuildDate>
    <atom:link href="https://pfcomputing.com/en/categories/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>[Notice] Mitigation for GhostLock (CVE-2026-43499) Completed</title>
      <link>https://pfcomputing.com/en/news/20260723/</link>
      <pubDate>Thu, 23 Jul 2026 13:00:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20260723/</guid>
      <description><![CDATA[<p>A local privilege escalation vulnerability in the Linux kernel, <strong>GhostLock (CVE-2026-43499)</strong>, has been disclosed.</p>
<p>To address this vulnerability, PFCP completed emergency maintenance on July 23, 2026, during which we updated the Linux kernel on the host operating system of PFCP-managed Kubernetes nodes.</p>
<p><strong>Mitigation</strong></p>
<p>The Linux kernel on the host operating system (Ubuntu 24.04 LTS) of PFCP-managed Kubernetes nodes has been updated to <strong>6.8.0-136.136</strong>, which addresses GhostLock (CVE-2026-43499).</p>
<p><strong>Completion Time</strong></p>
<p>July 23, 2026, 12:00 JST</p>
<p><strong>Customer Action Required</strong></p>
<p>No action is required from PFCP users.</p>
<p>For details of the maintenance associated with this update, please refer to the following announcement.</p>
<ul>
<li><a href="https://pfcomputing.com/news/20260721-2/">https://pfcomputing.com/news/20260721-2/</a></li>
</ul>
<p><strong>References</strong></p>
<ul>
<li>Ubuntu Security Notice: <a href="https://ubuntu.com/security/CVE-2026-43499">https://ubuntu.com/security/CVE-2026-43499</a></li>
</ul>
<hr>
<p>PFCP is committed to providing timely security updates so that our users can continue to use our services with confidence.</p>
]]></description>
    </item>
    <item>
      <title>[Report] Authentication Misconfiguration Fix</title>
      <link>https://pfcomputing.com/en/news/20260512-2/</link>
      <pubDate>Tue, 12 May 2026 17:00:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20260512-2/</guid>
      <description><![CDATA[<p>A misconfiguration was found in part of the authentication settings for PFCP&rsquo;s Kubernetes clusters.</p>
<p>Under certain conditions, HTTP access through PFCP&rsquo;s Identity-Aware Proxy could have allowed access to Pods in namespaces that the user was not authorized to access.</p>
<p>In response, the ExternalName Service feature used in the affected access path has been disabled, and the related authentication settings have been reviewed. This issue has been resolved.</p>
<p><strong>Mitigation:</strong></p>
<ul>
<li>Disabled ExternalName Service.</li>
<li>Reviewed related authentication settings.</li>
</ul>
<p><strong>Completion Date:</strong></p>
<p>May 12, 2026</p>
<p><strong>User Impact:</strong></p>
<p>No action is required from users. You can continue using the service as usual.</p>
<hr>
<p>PFCP remains committed to maintaining and improving security so that users can use the service with confidence.</p>
]]></description>
    </item>
    <item>
      <title>[Report] Initial Mitigation Completed for Linux Kernel Vulnerability</title>
      <link>https://pfcomputing.com/en/news/20260508/</link>
      <pubDate>Fri, 08 May 2026 11:50:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20260508/</guid>
      <description><![CDATA[<p>A high-severity vulnerability was reported in the Linux kernel. PFCP has disabled the vulnerable feature in its Kubernetes clusters, completing the initial mitigation.</p>
<p><strong>Mitigation:</strong></p>
<p>Disabled the vulnerable feature.</p>
<p><strong>Completion Time:</strong></p>
<p>May 8, 2026, 12:00 JST</p>
<p><strong>User Impact:</strong></p>
<p>No action is required from users. You can continue using the service as usual.</p>
<p><strong>Vulnerability Details:</strong></p>
<p>No CVE has been assigned, but please refer to the following information.</p>
<ul>
<li><a href="https://blog.cloudlinux.com/dirty-frag-mitigation-and-kernel-update">https://blog.cloudlinux.com/dirty-frag-mitigation-and-kernel-update</a></li>
</ul>
<hr>
<p>PFCP is committed to providing prompt security updates so that users can use the service with confidence.</p>
]]></description>
    </item>
    <item>
      <title>[Report] Initial Mitigation Completed for Linux Kernel Vulnerability</title>
      <link>https://pfcomputing.com/en/news/20260430/</link>
      <pubDate>Thu, 30 Apr 2026 15:00:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20260430/</guid>
      <description><![CDATA[<p>A high-severity vulnerability was reported in the Linux kernel. PFCP has disabled the vulnerable feature in its Kubernetes clusters, completing the initial mitigation.</p>
<p><strong>Mitigation:</strong></p>
<p>Disabled the vulnerable feature.</p>
<p><strong>Completion Date:</strong></p>
<p>April 30, 2026</p>
<p><strong>User Impact:</strong></p>
<p>No action is required from users. You can continue using the service as usual.</p>
<p><strong>Vulnerability Details:</strong></p>
<ul>
<li>CVE-2026-31431: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31431">https://nvd.nist.gov/vuln/detail/CVE-2026-31431</a></li>
</ul>
<hr>
<p>PFCP is committed to providing prompt security updates so that users can use the service with confidence.</p>
]]></description>
    </item>
    <item>
      <title>[Important] Emergency Security Response and Re-Login Request Following Compromise of Python Package &#34;litellm&#34;</title>
      <link>https://pfcomputing.com/en/news/20260325/</link>
      <pubDate>Wed, 25 Mar 2026 16:00:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20260325/</guid>
      <description><![CDATA[<p>The Python package &ldquo;litellm&rdquo; was found to be compromised, with malicious code embedded that steals credentials.</p>
<p>This is an extremely serious incident: the malicious code can execute simply by having the package installed. To ensure the security of the entire cluster, PFCP has taken emergency security measures.</p>
<p>We apologize for the inconvenience. Please review the following information and take the necessary action (re-login) as described below.</p>
<p><strong>Security measures taken:</strong></p>
<ul>
<li>Action: Forced reset of kubectl credentials (tokens)</li>
<li>Time: March 25, 2026, 13:00 JST</li>
</ul>
<p>As a result of this action, all existing credentials have been invalidated. You will need to re-login before using kubectl going forward.</p>
<p><strong>Impact:</strong></p>
<ul>
<li>All existing kubectl credentials have been invalidated.</li>
<li>Authentication errors will occur when running kubectl commands.</li>
<li>Running workloads are not affected.</li>
</ul>
<p><strong>How to re-login:</strong></p>
<p>Please follow the steps in the documentation below to log in again.</p>
<p><a href="https://docs.pfcomputing.com/cluster/connect-to-cluster.html">https://docs.pfcomputing.com/cluster/connect-to-cluster.html</a></p>
<p><strong>Background (overview of the litellm compromise):</strong></p>
<p>Versions 1.82.7 and 1.82.8 of &ldquo;litellm&rdquo; contained code that exfiltrated sensitive information—including environment variables and Kubernetes configuration (<code>~/.kube/config</code>)—to an external server.</p>
<p>The malicious code executes simply by starting a Python process. Because Kubernetes tokens may have been stolen without your knowledge, PFCP performed a cluster-wide reset.</p>
<p><strong>Action requested of users:</strong></p>
<ol>
<li>Immediately check whether the affected version is installed in your PFCP execution environment and on your local PC.
<ul>
<li>Check command: <code>pip list | grep litellm</code></li>
</ul>
</li>
<li>Treat all secrets (SSH keys, cloud service API keys, etc.) accessible from any environment where this package was installed as potentially compromised, and revoke and reissue them.</li>
</ol>
<p><strong>Detailed information (GitHub Issue):</strong></p>
<p><a href="https://github.com/BerriAI/litellm/issues/24512">https://github.com/BerriAI/litellm/issues/24512</a></p>
<hr>
<p>We apologize for the inconvenience and appreciate your understanding and cooperation as we take these necessary steps to maintain security.</p>
]]></description>
    </item>
    <item>
      <title>[Report] Mitigation complete for ingress-nginx vulnerabilities</title>
      <link>https://pfcomputing.com/en/news/20260204/</link>
      <pubDate>Wed, 04 Feb 2026 09:00:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20260204/</guid>
      <description><![CDATA[<p>Four vulnerabilities, including high-severity issues, were reported in ingress-nginx, the open-source software used for workload publishing. PFCP has completed mitigation by upgrading Kubernetes clusters to a fixed version.</p>
<p><strong>Mitigation Details:</strong></p>
<p>ingress-nginx version upgrade (v1.14.3)</p>
<p><strong>Mitigation Completion Date:</strong></p>
<p>2026/02/04</p>
<p><strong>User Impact:</strong></p>
<p>No action is required on the user side. You can continue using the service as usual.</p>
<p><strong>Vulnerability Details:</strong></p>
<ul>
<li>CVE-2026-1580: <a href="https://github.com/kubernetes/kubernetes/issues/136677">https://github.com/kubernetes/kubernetes/issues/136677</a></li>
<li>CVE-2026-24512: <a href="https://github.com/kubernetes/kubernetes/issues/136678">https://github.com/kubernetes/kubernetes/issues/136678</a></li>
<li>CVE-2026-24513: <a href="https://github.com/kubernetes/kubernetes/issues/136679">https://github.com/kubernetes/kubernetes/issues/136679</a></li>
<li>CVE-2026-24514: <a href="https://github.com/kubernetes/kubernetes/issues/136680">https://github.com/kubernetes/kubernetes/issues/136680</a></li>
</ul>
<hr>
<p>PFCP will continue to provide timely security updates so users can use our services with confidence.</p>
]]></description>
    </item>
    <item>
      <title>[Report] Mitigation complete for runc vulnerabilities</title>
      <link>https://pfcomputing.com/en/news/20251105/</link>
      <pubDate>Wed, 05 Nov 2025 19:00:00 +0900</pubDate>
      <guid>https://pfcomputing.com/en/news/20251105/</guid>
      <description><![CDATA[<p>Three high-severity vulnerabilities were reported in the container runtime runc. PFCP has already upgraded all Kubernetes clusters to a fixed version.</p>
<p>For details on the vulnerabilities, please refer to the links below.</p>
<ul>
<li>runc version: 1.3.0 -&gt; 1.3.3</li>
<li>runc release notes: <a href="https://github.com/opencontainers/runc/releases/tag/v1.3.3">https://github.com/opencontainers/runc/releases/tag/v1.3.3</a></li>
<li>CVE IDs
<ul>
<li>CVE-2025-31133 (CVSS v4: 7.3): <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2">https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2</a></li>
<li>CVE-2025-52881 (CVSS v4: 7.3): <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm">https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm</a></li>
<li>CVE-2025-52565 (CVSS v4: 7.3): <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r">https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r</a></li>
</ul>
</li>
</ul>
]]></description>
    </item>
  </channel>
</rss>
