dnf update aborts on CL9 + EPEL: ea-php81-85-php-gd and alt-php GD require libavif.so.15, EPEL 9 libavif 1.1.1 clashes with alt-common libavif/svt-av1-libs
Subscribe
Update - We are continuing to investigate this issue.
Sep 29, 2026 - 16:28 UTC
Sep 29, 2026 - 16:28 UTC
Investigating - On CL9 cPanel servers with EPEL enabled (default best=True), `dnf update` / upcp aborts completely:
"package ea-php8X-php-gd ... requires libavif.so.15()(64bit), but none of the providers can be installed".
To let updates proceed, add this line to the [epel] section of /etc/yum.repos.d/epel.repo and run your update again:
excludepkgs=libavif* svt-av1*
This is a temporary workaround. Remove the exclude once the fix (ALTPHP-2626) is released. A regular dnf update will then complete normally.
Sep 29, 2026 - 15:33 UTC
"package ea-php8X-php-gd ... requires libavif.so.15()(64bit), but none of the providers can be installed".
To let updates proceed, add this line to the [epel] section of /etc/yum.repos.d/epel.repo and run your update again:
excludepkgs=libavif* svt-av1*
This is a temporary workaround. Remove the exclude once the fix (ALTPHP-2626) is released. A regular dnf update will then complete normally.
Sep 29, 2026 - 15:33 UTC
Update - The patched CloudLinux 7h and CloudLinux 8 kernels have moved out of beta. A staged rollout to the stable channel began on September 23, 2026, so servers on the stable channel pick the update up progressively rather than all at once. Target versions are unchanged: kernel-4.18.0-553.157.1.lve.2.el8 and kernel-4.18.0-553.157.1.lve.2.el7h.
To install now rather than wait for the rollout to reach your server, use the beta-channel commands below and reboot. Once the rollout completes, the standard yum update 'kernel*' followed by a reboot is enough.
Sep 24, 2026 - 20:00 UTC
To install now rather than wait for the rollout to reach your server, use the beta-channel commands below and reboot. Once the rollout completes, the standard yum update 'kernel*' followed by a reboot is enough.
Sep 24, 2026 - 20:00 UTC
Update - KernelCare livepatches for CloudLinux 7h and CloudLinux 8 are on the main feed. The CloudLinux 7h patch covers the kernel 4.18.0-553.157.1.lve.2.el7h. Subscribed servers take them on their next update cycle.
Sep 23, 2026 - 19:42 UTC
Sep 23, 2026 - 19:42 UTC
Update - Status summary as of September 23, 2026
CloudLinux 7:
Patch under assessment. Not exposed to ordinary accounts by default.
CloudLinux 7h and CloudLinux 8 (exposed by default):
Fixed kernel 4.18.0-553.157.1.lve.2 is in the beta channel; KernelCare livepatch is on the testing feed kcarectl --update --prefix test.
Stable/main-feed release will follow the normal schedule.
CloudLinux 8 LTS (exposed by default):
Patched kernel in preparation. KernelCare does not cover this kernel line. Keep the modprobe mitigation in place until the fixed kernel ships.
CloudLinux 9:
KernelCare livepatch on the main feed kernel 5.14.0-687.46.1.el9_8.
Not exposed to ordinary accounts by default.
CloudLinux 9 LTS:
Patch in preparation. Not exposed to ordinary accounts by default.
CloudLinux 10: KernelCare livepatch on the main feed kernel 6.12.0-211.53.1.el10_2.
Not exposed to ordinary accounts by default.
Verify a KernelCare-patched server with:
kcarectl --patch-info | grep CVE-2026-72389
Full details and mitigation instructions: https://blog.cloudlinux.com/bridge-stp-uaf-cve-2026-72389-kernel-update-cloudlinux
Sep 22, 2026 - 23:05 UTC
CloudLinux 7:
Patch under assessment. Not exposed to ordinary accounts by default.
CloudLinux 7h and CloudLinux 8 (exposed by default):
Fixed kernel 4.18.0-553.157.1.lve.2 is in the beta channel; KernelCare livepatch is on the testing feed kcarectl --update --prefix test.
Stable/main-feed release will follow the normal schedule.
CloudLinux 8 LTS (exposed by default):
Patched kernel in preparation. KernelCare does not cover this kernel line. Keep the modprobe mitigation in place until the fixed kernel ships.
CloudLinux 9:
KernelCare livepatch on the main feed kernel 5.14.0-687.46.1.el9_8.
Not exposed to ordinary accounts by default.
CloudLinux 9 LTS:
Patch in preparation. Not exposed to ordinary accounts by default.
CloudLinux 10: KernelCare livepatch on the main feed kernel 6.12.0-211.53.1.el10_2.
Not exposed to ordinary accounts by default.
Verify a KernelCare-patched server with:
kcarectl --patch-info | grep CVE-2026-72389
Full details and mitigation instructions: https://blog.cloudlinux.com/bridge-stp-uaf-cve-2026-72389-kernel-update-cloudlinux
Sep 22, 2026 - 23:05 UTC
Update - KernelCare livepatches for CloudLinux 7h and CloudLinux 8 have reached the testing feed. The CloudLinux 7h patch covers kernel 4.18.0-553.157.1.lve.2.el7h. Servers on the default feed do not have these yet; to take one from the testing feed now:
kcarectl --update --prefix test
Sep 22, 2026 - 23:05 UTC
kcarectl --update --prefix test
Sep 22, 2026 - 23:05 UTC
Update - The KernelCare livepatch for CloudLinux 10 is on the main feed and covers the CloudLinux 10 kernel 6.12.0-211.53.1.el10_2. Subscribed servers take it on their next update cycle. Livepatches for CloudLinux 7h and CloudLinux 8 are still in preparation.
Sep 19, 2026 - 04:00 UTC
Sep 19, 2026 - 04:00 UTC
Update - The KernelCare livepatch for CloudLinux 9 is now on the main feed, covering kernel 5.14.0-687.46.1.el9_8. Subscribed servers receive it automatically on the next update cycle, or immediately with kcarectl --update; verify with kcarectl --patch-info | grep CVE-2026-72389.
Sep 15, 2026 - 23:51 UTC
Sep 15, 2026 - 23:51 UTC
Identified - bridge-stp-uaf (CVE-2026-72389, CVSS 7.0, Moderate per Red Hat) is a vulnerability in the Linux kernel’s bridge Spanning Tree Protocol timers. A local unprivileged user who can configure a network bridge can turn it into root on the host. The researchers published helper code rather than a working exploit, and none has appeared publicly since.
Affected: → Affected CloudLinux versions
CloudLinux 7h, CloudLinux 8 and CloudLinux 8 LTS, where an ordinary hosting account reaches the flaw as shipped.
The vulnerable code is in every CloudLinux kernel, but CloudLinux 7, 9, 9 LTS, 10 and CloudLinux for Ubuntu 22.04 are not exposed to ordinary accounts by default.
Mitigation: one modprobe rule that stops the bridge module from loading. No reboot on hosts that do not bridge. → Is there a mitigation?
Fix status → Update instructions
CloudLinux 7h and 8 kernel: patched kernels 4.18.0-553.157.1.lve.2 are in the beta channel; promotion to stable follows on the normal schedule. → Stream 1
AlmaLinux kernel (CloudLinux 9, 10): no fixed kernel yet. Red Hat lists its kernels as affected with no fix published, and AlmaLinux follows Red Hat. Both versions are not exposed by default. → Stream 2
CloudLinux 8 LTS and 9 LTS kernel (TuxCare ELS): in preparation. → Stream 3
KernelCare livepatch: in preparation. → Stream 4
Verify: uname -r against the target version in your stream; kcarectl –patch-info | grep CVE-2026-72389 once a livepatch ships. → How to verify you are patched
Why it matters: on a shared host the local user is whoever compromised one of your sites, and root on the kernel is root over every tenant. → Why this matters on a shared host
How the bug works: a topology-change timer can be armed on a bridge that is already down, and deleting the bridge frees it with the timer still queued. → Technical details of the bug
Sep 10, 2026 - 17:53 UTC
Affected: → Affected CloudLinux versions
CloudLinux 7h, CloudLinux 8 and CloudLinux 8 LTS, where an ordinary hosting account reaches the flaw as shipped.
The vulnerable code is in every CloudLinux kernel, but CloudLinux 7, 9, 9 LTS, 10 and CloudLinux for Ubuntu 22.04 are not exposed to ordinary accounts by default.
Mitigation: one modprobe rule that stops the bridge module from loading. No reboot on hosts that do not bridge. → Is there a mitigation?
Fix status → Update instructions
CloudLinux 7h and 8 kernel: patched kernels 4.18.0-553.157.1.lve.2 are in the beta channel; promotion to stable follows on the normal schedule. → Stream 1
AlmaLinux kernel (CloudLinux 9, 10): no fixed kernel yet. Red Hat lists its kernels as affected with no fix published, and AlmaLinux follows Red Hat. Both versions are not exposed by default. → Stream 2
CloudLinux 8 LTS and 9 LTS kernel (TuxCare ELS): in preparation. → Stream 3
KernelCare livepatch: in preparation. → Stream 4
Verify: uname -r against the target version in your stream; kcarectl –patch-info | grep CVE-2026-72389 once a livepatch ships. → How to verify you are patched
Why it matters: on a shared host the local user is whoever compromised one of your sites, and root on the kernel is root over every tenant. → Why this matters on a shared host
How the bug works: a topology-change timer can be armed on a bridge that is already down, and deleting the bridge frees it with the timer still queued. → Technical details of the bug
Sep 10, 2026 - 17:53 UTC
About This Site
Welcome to CloudLinux status page. Here you can see if there are any ongoing issues with the CloudLinux network or other services.
CloudLinux OS Components
Operational
Alt-PHP
Operational
CageFS
Operational
MySQL Governor
Operational
EasyApache4 PHP packages
Operational
CloudLinux Kernel
Operational
Mod_lsapi
Operational
PHP Selector
Operational
Python Selector
Operational
Ruby Selector
Operational
Node.js Selector
Operational
CloudLinux Network
Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance