Upsun (formerly Platform.sh)

5.5K posts

Upsun (formerly Platform.sh) banner
Upsun (formerly Platform.sh)

Upsun (formerly Platform.sh)

@upsundotcom

The cloud application platform humans and robots love ❤️

The universe, and beyond Katılım Nisan 2014
2.5K Takip Edilen5K Takipçiler
Sabitlenmiş Tweet
Upsun (formerly Platform.sh)
Upsun (formerly Platform.sh)@upsundotcom·
Over the weekend, we responded to the critical "DirtyFrag" Linux vulnerability (CVE-2026-43284 and CVE-2026-43500) by deploying an emergency kernel patch across all regions. While our systems are not affected by the RxRPC vulnerability (CVE-2026-43500) as we don't compile that kernel module, we were affected by the IPsec ESP vulnerability (CVE-2026-43284) and needed to apply patches immediately. To protect your data and minimize exploitation risk during the rollout, we temporarily restricted SSH and deployment access and performed brief service restarts. While this vulnerability "only" provided root access within affected systems, we recognize that such exploits are typically used as the first step in a chain of attacks, potentially leading to container escapes and broader infrastructure compromise. Given this risk, we chose to err on the side of caution by implementing temporary access restrictions during our update window. We understand this disruption was inconvenient, and the decision to disable SSH access was not made lightly. However, we believe these swift and decisive actions were essential to safeguarding your systems and data. Our priority is always to maintain the security and integrity of your infrastructure. All services have now been fully restored, and you can access your projects and deployments as normal. If you're still experiencing any issues, please don't hesitate to contact our support team. We appreciate your patience and understanding as we work to keep your hosting environment secure.
English
0
2
6
476