The kernel patch for new CVEs is currently under development

Incident Report for CloudLinux

Resolved

This incident has been resolved.
Posted Apr 10, 2021 - 17:29 UTC

Monitoring

A fix has been implemented and we are monitoring the results.
Posted Apr 10, 2021 - 17:26 UTC

Update

Patches have now been released for CentOS 8, Oracle EL8, RHEL8, CloudLinux 7h, CloudLinux 8, AlmaLinux OS, Ubuntu Bionic HWE, Debian 10, Debian 10 Cloud, Debian 9 Backports and Proxmox VE6.

Additionally, patches are now also available for CloudLinux 6h, CloudLinux 7, CentOS 7, CentOS 7-plus, Oracle EL7, and RHEL 7.
Posted Mar 17, 2021 - 16:59 UTC

Identified

KernelCare patches should be developed by the end of a week. We'll keep you posted.
Posted Mar 15, 2021 - 14:39 UTC

Investigating

3 vulnerabilities found in the iSCSI code of Linux:
CVE-2021-27363
CVE-2021-27364
CVE-2021-27365

More info here.

Our developers are working on the patch for CloudLinux kernels as well as KernelCare. We will keep updating the status of this issue.
Posted Mar 13, 2021 - 20:05 UTC
This incident affected: CloudLinux OS Components (CloudLinux Kernel).