Vserver is a lightweight virtualization system for Linux that partitions a single kernel into isolated virtual servers, supported by a narrow but specialized product line including the core Linux-VServer kernel patch and its associated utility suite. While its disclosures cluster around the generic "Other" classification, the vendor's vulnerabilities have an elevated tendency toward public exploit availability, reflecting the security-critical role container-isolation mechanisms play in multi-tenant environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vserver over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2613HIGH Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspe | Dec 31, 2004 | 10.0 | 31 | NO | NO |
CVE-2004-2073HIGH Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using | Feb 6, 2004 | 7.2 | 28 | NO | YES |
CVE-2005-4418HIGH util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could | Dec 31, 2005 | 7.5 | 20 | NO | NO |
CVE-2003-1288MEDIUM Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to t | Dec 31, 2003 | 5.0 | 19 | NO | NO |
CVE-2006-1656HIGH vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dang | Apr 6, 2006 | 7.2 | 18 | NO | NO |
CVE-2005-0178MEDIUM Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY | Mar 7, 2005 | 6.2 | 17 | NO | NO |
Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and host servers, which allows local users with the ability to | Dec 31, 2004 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vserver.
Media articles that mention a CVE ID that affects a product developed by Vserver — matched by CVE ID, not by vendor name.